← advisory ledger

ADVISORY UNAUTH-2026-0013
TYPE exposure-class
PRODUCT AnythingLLM
SEVERITY CRITICAL

CRITICAL

AnythingLLM open without authentication

published 2026-08-05 · updated 2026-08-05

Why it matters

Your AnythingLLM answers anyone on the internet with no login at all. Strangers can chat with your models (you pay for the tokens or the GPU), read every document you uploaded for RAG, and change your settings.

What a probe sees

GET :3001/ serves the AnythingLLM app with no login — single-user mode has no auth at all.

Internet-facing exposure — observable from the public internet with GET-only probes (the same probes unauth.dev sends).

no-auth-by-design

In the wild

No honeypot telemetry for this service yet (in_the_wild: null in the dataset). We do not invent numbers. The block appears when the honeypot has real data.

Fix it

Fix card: anythingllm-exposed →

References

Cite this record

unauth.dev advisory UNAUTH-2026-0013 — published 2026-08 · CC-BY 4.0

Canonical URL: https://unauth.dev/advisories/UNAUTH-2026-0013. This record is part of the unauth.dev advisory dataset, published under CC-BY 4.0: attribute "unauth.dev / Raúl Acedo". Schema: additive-only within v1; this id will never be renumbered or reused.