Description
Anytype Heart is the middleware library for Anytype. The challenge-based authentication for the local gRPC client API can be bypassed, allowing an attacker to gain access without the 4-digit code. This vulnerability is fixed in anytype-heart 0.48.4, anytype-cli 0.1.11, and Anytype Desktop 0.54.5.
Published: 2026-03-11
Score: 3.6 Low
EPSS: < 1% Very Low
KEV: No
Impact: Unauthorized Access via Authentication Bypass
Action: Immediate Patch
AI Analysis

Analysis and contextual insights are available on OpenCVE Cloud.

Remediation

No vendor fix or workaround currently provided.

Additional remediation guidance may be available on OpenCVE Cloud.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Github GHSA Github GHSA GHSA-vv3h-7qwr-722v Anytype Heart's gRPC API client challenge verification can be bypassed on localhost
History

Fri, 20 Mar 2026 16:30:00 +0000

Type Values Removed Values Added
First Time appeared Anytype
Anytype anytype Cli
Anytype anytype Desktop
Anytype anytype Heart
CPEs cpe:2.3:a:anytype:anytype_cli:*:*:*:*:*:*:*:*
cpe:2.3:a:anytype:anytype_desktop:*:*:*:*:*:*:*:*
cpe:2.3:a:anytype:anytype_heart:*:*:*:*:*:*:*:*
Vendors & Products Anytype
Anytype anytype Cli
Anytype anytype Desktop
Anytype anytype Heart

Thu, 12 Mar 2026 14:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 12 Mar 2026 10:15:00 +0000

Type Values Removed Values Added
First Time appeared Anyproto
Anyproto anytype-cli
Anyproto anytype-heart
Anyproto anytype-ts
Vendors & Products Anyproto
Anyproto anytype-cli
Anyproto anytype-heart
Anyproto anytype-ts

Wed, 11 Mar 2026 18:00:00 +0000

Type Values Removed Values Added
Description Anytype Heart is the middleware library for Anytype. The challenge-based authentication for the local gRPC client API can be bypassed, allowing an attacker to gain access without the 4-digit code. This vulnerability is fixed in anytype-heart 0.48.4, anytype-cli 0.1.11, and Anytype Desktop 0.54.5.
Title Improper Restriction of Excessive Authentication Attempts in github.com/anyproto/anytype-heart
Weaknesses CWE-307
References
Metrics cvssV3_1

{'score': 3.6, 'vector': 'CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N'}


Subscriptions

Anyproto Anytype-cli Anytype-heart Anytype-ts
Anytype Anytype Cli Anytype Desktop Anytype Heart
cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-03-12T13:52:12.763Z

Reserved: 2026-03-09T19:02:25.013Z

Link: CVE-2026-31863

cve-icon Vulnrichment

Updated: 2026-03-12T13:52:06.399Z

cve-icon NVD

Status : Analyzed

Published: 2026-03-11T18:16:25.270

Modified: 2026-03-20T16:29:45.237

Link: CVE-2026-31863

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-16T09:30:06Z

Weaknesses