ADVISORY UNAUTH-2026-0013
TYPE exposure-class
PRODUCT AnythingLLM
SEVERITY CRITICAL
AnythingLLM open without authentication
published 2026-08-05 · updated 2026-08-05
Why it matters
Your AnythingLLM answers anyone on the internet with no login at all. Strangers can chat with your models (you pay for the tokens or the GPU), read every document you uploaded for RAG, and change your settings.
What a probe sees
GET :3001/ serves the AnythingLLM app with no login — single-user mode has no auth at all.
Internet-facing exposure — observable from the public internet with GET-only probes (the same probes unauth.dev sends).
no-auth-by-design
In the wild
No honeypot telemetry for this service yet (in_the_wild: null in the dataset). We do not invent numbers. The block appears when the honeypot has real data.
Fix it
Fix card: anythingllm-exposed →
References
Cite this record
unauth.dev advisory UNAUTH-2026-0013 — published 2026-08 · CC-BY 4.0
Canonical URL: https://unauth.dev/advisories/UNAUTH-2026-0013. This record is part of the unauth.dev advisory dataset, published under CC-BY 4.0: attribute "unauth.dev / Raúl Acedo". Schema: additive-only within v1; this id will never be renumbered or reused.