Ad

CVE-2026-31863

MEDIUM CVSS 3.1: 4.4 EPSS 0.02%
Updated Mar 20, 2026
Anytype
Parameter Value
CVSS 4.4 (MEDIUM)
Affected Versions before 0.54.5
Fixed In 0.1.11
Type CWE-307
Vendor Anytype
Public PoC No

Anytype Heart is the middleware library for Anytype. The challenge-based authentication for the local gRPC client API can be bypassed, allowing an attacker to gain access without the 4-digit code. This vulnerability is fixed in anytype-heart 0.48.4, anytype-cli 0.1.11, and Anytype Desktop 0.54.5.

Attack Parameters

Attack Vector
Local
Requires local access
Attack Complexity
Low
Easy to exploit
Privileges Required
Low
Basic privileges needed
User Interaction
None
No user interaction needed

Impact Assessment

Confidentiality
Low
Partial data leak
Integrity
Low
Partial data modification
Availability
None
No disruption

CVSS Vector v3.1

Weakness Type (CWE)

Vulnerable Products 3

Configuration From (including) Up to (excluding)
Anytype Anytype_Cli
cpe:2.3:a:anytype:anytype_cli:*:*:*:*:*:*:*:*
0.1.11
Anytype Anytype_Desktop
cpe:2.3:a:anytype:anytype_desktop:*:*:*:*:*:*:*:*
0.54.5
Anytype Anytype_Heart
cpe:2.3:a:anytype:anytype_heart:*:*:*:*:*:*:*:*
0.48.4