GHSA-mq4x-r3rg-g5rqHighCVSS 7.5
QAnything 2.0.0 contains an authentication bypass vulnerability in the /api/local_doc_qa...
🔗 CVE IDs covered (1)
📋 Description
QAnything 2.0.0 contains an authentication bypass vulnerability in the /api/local_doc_qa/get_file_base64 and /api/local_doc_qa/get_doc endpoints that allows unauthenticated attackers to access any uploaded file or document. Attackers can enumerate file identifiers through unauthenticated endpoints and retrieve base64-encoded files or parsed document chunks without ownership verification to disclose cross-tenant knowledge base content.
🔗 References (6)
- https://nvd.nist.gov/vuln/detail/CVE-2026-85671
- https://github.com/netease-youdao/QAnything/issues/670
- https://github.com/netease-youdao/QAnything
- https://github.com/netease-youdao/QAnything/blob/v2.0.0/qanything_kernel/qanything_server/handler.py
- https://www.vulncheck.com/advisories/qanything-2.0.0-unauthenticated-cross-user-file-disclosure
- https://github.com/advisories/GHSA-mq4x-r3rg-g5rq