« Volver al listado

CVE-2026-31863

Estado: AnalizadaMedia (4.4)—

Anytype Heart is the middleware library for Anytype. The challenge-based authentication for the local gRPC client API can be bypassed, allowing an attacker to gain access without the 4-digit code. This vulnerability is fixed in anytype-heart 0.48.4, anytype-cli 0.1.11, and Anytype Desktop 0.54.5.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (3)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2026-31863",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2026-31863",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "none"
            },
            {
              "automatable": "no"
            },
            {
              "technicalImpact": "partial"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2026-03-12T13:52:02.447723Z"
        }
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "security-advisories@github.com",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 3.6,
          "attackVector": "LOCAL",
          "baseSeverity": "LOW",
          "vectorString": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N",
          "integrityImpact": "LOW",
          "userInteraction": "NONE",
          "attackComplexity": "HIGH",
          "availabilityImpact": "NONE",
          "privilegesRequired": "LOW",
          "confidentialityImpact": "LOW"
        },
        "impactScore": 2.5,
        "exploitabilityScore": 1
      },
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 4.4,
          "attackVector": "LOCAL",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N",
          "integrityImpact": "LOW",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "NONE",
          "privilegesRequired": "LOW",
          "confidentialityImpact": "LOW"
        },
        "impactScore": 2.5,
        "exploitabilityScore": 1.8
      }
    ]
  },
  "affected": [
    {
      "source": "security-advisories@github.com",
      "affectedData": [
        {
          "vendor": "anyproto",
          "product": "anytype-heart",
          "versions": [
            {
              "status": "affected",
              "version": "< 0.48.4"
            }
          ]
        },
        {
          "vendor": "anyproto",
          "product": "anytype-cli",
          "versions": [
            {
              "status": "affected",
              "version": "< 0.1.11"
            }
          ]
        },
        {
          "vendor": "anyproto",
          "product": "anytype-ts",
          "versions": [
            {
              "status": "affected",
              "version": "< 0.54.5"
            }
          ]
        }
      ]
    }
  ],
  "published": "2026-03-11T18:16:25.270",
  "references": [
    {
      "url": "https://github.com/anyproto/anytype-heart/security/advisories/GHSA-vv3h-7qwr-722v",
      "tags": [
        "Patch",
        "Vendor Advisory"
      ],
      "source": "security-advisories@github.com"
    }
  ],
  "vulnStatus": "Analyzed",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "security-advisories@github.com",
      "description": [
        {
          "lang": "en",
          "value": "CWE-307"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "Anytype Heart is the middleware library for Anytype. The challenge-based authentication for the local gRPC client API can be bypassed, allowing an attacker to gain access without the 4-digit code. This vulnerability is fixed in anytype-heart 0.48.4, anytype-cli 0.1.11, and Anytype Desktop 0.54.5."
    },
    {
      "lang": "es",
      "value": "Anytype Heart es la biblioteca de middleware para Anytype. La autenticación basada en desafíos para la API de cliente gRPC local puede ser eludida, permitiendo a un atacante obtener acceso sin el código de 4 dígitos. Esta vulnerabilidad está corregida en anytype-heart 0.48.4, anytype-cli 0.1.11 y Anytype Desktop 0.54.5."
    }
  ],
  "lastModified": "2026-06-17T10:34:39.330",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:anytype:anytype_cli:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "48E258B4-F304-4C04-8447-062E18AD427E",
              "versionEndExcluding": "0.1.11"
            },
            {
              "criteria": "cpe:2.3:a:anytype:anytype_desktop:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "06C0A410-2ED2-4A69-9FE4-5153F7D29887",
              "versionEndExcluding": "0.54.5"
            },
            {
              "criteria": "cpe:2.3:a:anytype:anytype_heart:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "061F6964-1440-48DC-B1A9-02F59BFC24C1",
              "versionEndExcluding": "0.48.4"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "security-advisories@github.com"
}