Executive brief
QAnything is a document question-answering application that allows organizations to upload and query knowledge bases. Version 2.0.0 contains a flaw in two API endpoints (/api/local_doc_qa/get_file_base64 and /api/local_doc_qa/get_doc) that fails to verify user authentication and document ownership, allowing anyone with network access to retrieve and read any uploaded file or document without logging in. An attacker can extract sensitive business documents, customer data, and proprietary information from any knowledge base in the system.
Technical details
QAnything 2.0.0 contains an authentication bypass vulnerability in the /api/local_doc_qa/get_file_base64 and /api/local_doc_qa/get_doc API endpoints. The vulnerable endpoints fail to enforce authentication checks and document ownership validation, allowing unauthenticated network attackers to enumerate file and document identifiers through other unauthenticated endpoints and retrieve the base64-encoded file contents or parsed document chunks without any authorization. An attacker can systematically access cross-tenant knowledge base content by iterating through identifiers, resulting in confidentiality breach affecting all stored documents. The vulnerability is present in the sanic_api.py and handler.py request handling code in version 2.0.0 and requires no user interaction or authentication.
Affected products
- Netease QAnything 2.0.0
Timeline
- 2026-09-04: disclosed