CVE-2026-72917: AnythingLLM is an application that turns pieces of content into context that any LLM can use as references during chatting. From 1.0.0 to 1.15.0, AnythingLLM's unauthenticated account-recovery flow...

Added to the CISA Known Exploited Vulnerabilities catalog on 10 Aug 2026. Vendor: AI/ML. Product: LLM. CVSS score: 5.9.

AnythingLLM is an application that turns pieces of content into context that any LLM can use as references during chatting. From 1.0.0 to 1.15.0, AnythingLLM's unauthenticated account-recovery flow in server/utils/PasswordRecovery/index.js uses recoverAccount() to deduplicate the raw recoveryCode...

Required action: Review and patch if applicable to your AI infrastructure.