CVE-2024-8026: Qanything

High severity, CVSS 8.1. EPSS: 0.2% chance of exploitation in the next 30 days.

A Cross-Site Request Forgery (CSRF) vulnerability exists in the backend API of netease-youdao/qanything, as of commit d9ab8bc. The backend server has overly permissive CORS headers, allowing all cross-origin calls. This vulnerability affects all backend endpoints, enabling actions such as creating, uploading, listing, deleting files, and managing knowledge bases.

Affected products

  • Qanything Qanything: up to and including 2024-06-24

Published 2025-03-20. Last modified 2026-06-17.