Reference page — cumulative record through Wednesday, August 19, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.
Mintplex-Labs anything-llm — AnythingLLM: Legacy mobile device tokens bypass multi-user workspace scoping after mode migration
AV AC PR UI S C I A CVSS EPSS %ile KEV
N L L N U L N N 4.3 .0022 12.7 —
AFFECTED
Product Versions Fixed
anything-llm < 1.13.0 – —
TIMELINE
May 19 Reserved by GitHub_M
May 28 EXPLOIT PUBLISHED — CVE-2026-47713 (Mintplex-Labs anything-llm). Public exploit reference added.
May 28 Published (CNA: GitHub_M)
Description
AnythingLLM is an application that turns pieces of content into context that any LLM can use as references during chatting. Prior to 1.13.0, an approved mobile device token created in single-user mode can survive single-user -> multi-user migration even when the device record has userId = null. In multi-user mode, that stale token is still accepted by the mobile authentication middleware. Because no user is attached to the request, downstream mobile handlers fall back to unscoped data-access branches and return workspaces and workspace content without per-user filtering. This permits a pre-migration mobile token to enumerate a workspace assigned only to another user and retrieve victim-owned thread metadata and chat content in multi-user mode. This vulnerability is fixed in 1.13.0.
Lifecycle
Complete event history — 3 events, chronological
| Date | Event | Detail |
| May 19, 2026 | Reserved | Reserved by GitHub_M |
| May 28, 2026 | EXPLOIT PUBLISHED | EXPLOIT PUBLISHED — CVE-2026-47713 (Mintplex-Labs anything-llm). Public exploit reference added. |
| May 28, 2026 | Published | Published (CNA: GitHub_M) |
Affected
Affected products and packages — 1 row
| Vendor | Product / Package | Ecosystem | Version introduced | Fixed |
| Mintplex-Labs | anything-llm | — | < 1.13.0 | — |
About this page
This is a reference page, not a dated page of record. It assembles the complete lifecycle of CVE-2026-47713 from the CVE Program record, NVD enrichment, the CISA KEV catalog, EPSS, and OSV advisories. The box score's numbers (CVSS, EPSS, KEV status) are current as of Wednesday, August 19, 2026 UTC and are re-derived as the archive grows; only dated daily editions are immutable pages of record. The authoritative source for this identifier is cve.org.