CVE-2026-21484

MEDIUM NUCLEI

AnythingLLM <e287fab56089cf8fcea9ba579a3ecdeca0daa313 - Info Disclo...

Title source: llm

Description

AnythingLLM is an application that turns pieces of content into context that any LLM can use as references during chatting. Prior to commit e287fab56089cf8fcea9ba579a3ecdeca0daa313, the password recovery endpoint returns different error messages depending on whether a username exists, so enabling username enumeration. Commit e287fab56089cf8fcea9ba579a3ecdeca0daa313 fixes this issue.

Nuclei Templates (1)

AnythingLLM - Username Enumeration via Password Recovery
MEDIUMVERIFIEDby DhiyaneshDk
Shodan: http.favicon.hash:-1279687529

Scores

CVSS v3 5.3
EPSS 0.0078
EPSS Percentile 73.7%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

Details

CWE
CWE-204 CWE-203
Status published
Products (1)
mintplexlabs/anythingllm < 1.10.0
Published Jan 03, 2026
Tracked Since Feb 18, 2026