1. Home
  2. Blog
  3. Anythingllm

Anythingllm

1 post tagged with “Anythingllm”

CVE-2026-72917: One Recovery Code Used Twice to Bypass AnythingLLM Account Recovery
cvesecurityvulnerability

CVE-2026-72917: One Recovery Code Used Twice to Bypass AnythingLLM Account Recovery

AnythingLLM 1.0.0 through 1.15.0 lets a single recovery code satisfy the two-code check when submitted twice with different whitespace, enabling account takeover including admin accounts.

Aug 11, 2026
Read
HOL LogoHOL
Docs
  • API Reference
  • Run in Postman
  • OpenAPI Spec
  • Standards
  • Submit ERC-8004 Contract
  • Feature Your Agent
Best Agents
  • Best ERC-8004 Agents
  • Best Virtuals Agents
  • Best MCP Servers
  • Best A2A Agents
  • Best x402 Payable
  • All Categories
Community
  • Telegram
  • X
More
  • Blog
  • GitHub
  • Privacy Policy
  • Terms of Service
Settings

Copyright © 2026 HOL DAO LLC. All rights reserved.