4.4
CVE-2026-31863
- EPSS 0.02%
- Veröffentlicht 11.03.2026 17:43:08
- Zuletzt bearbeitet 20.03.2026 16:29:45
- Quelle security-advisories@github.com
- CVE-Watchlists
- Unerledigt
Anytype Heart is the middleware library for Anytype. The challenge-based authentication for the local gRPC client API can be bypassed, allowing an attacker to gain access without the 4-digit code. This vulnerability is fixed in anytype-heart 0.48.4, anytype-cli 0.1.11, and Anytype Desktop 0.54.5.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Anytype ≫ Anytype Cli Version < 0.1.11
Anytype ≫ Anytype Desktop Version < 0.54.5
Anytype ≫ Anytype Heart Version < 0.48.4
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.02% | 0.05 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 4.4 | 1.8 | 2.5 |
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N
|
| security-advisories@github.com | 3.6 | 1 | 2.5 |
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N
|
CWE-307 Improper Restriction of Excessive Authentication Attempts
The product does not implement sufficient measures to prevent multiple failed authentication attempts within a short time frame.