Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

anything-llm — Vulnerabilities & Security Advisories 19

All 19 CVE vulnerabilities found in anything-llm, with AI-generated Chinese analysis, references, and POCs.

This vulnerability aggregation page catalogs security weaknesses identified in the AnythingLLM software package, specifically focusing on known flaws and their associated Common Weakness Enumerations. The collection aggregates disclosed issues affecting the AnythingLLM application, spanning advisories released over a multi-year period relevant to the product’s lifecycle. By consulting this index, developers and security analysts can track the evolution of security patches for the vendor’s releases, understand the recurrence of specific weakness classes within the codebase, and review the complete vulnerability history for the AnythingLLM product. The entries provide direct references to original security advisories and standardized weakness classifications, enabling a comprehensive view of the product’s security posture without requiring separate lookups across disparate databases.

Vendor: Mintplex-Labs

CVE ID Title CVSS Severity Published
CVE-2026-88055 AnythingLLM: Stored XSS Due to Unescaped Server-Side HTML Concatenation in MetaGenerator CWE-79 5.5 Medium 2026-09-10
CVE-2026-72917 AnythingLLM: Password recovery accepts one recovery code twice after whitespace normalization CWE-180 5.9 Medium 2026-08-10
CVE-2026-55611 AnythingLLM: embed-parsed-file cleanup deletes any parsed file by ID without ownership scoping (cross-tenant IDOR deletion) CWE-639 - - 2026-06-24
CVE-2026-48789 AnythingLLM: Windows path containment bypass in document folder route CWE-22 4.3 Medium 2026-06-24
CVE-2026-47713 AnythingLLM: Legacy mobile device tokens bypass multi-user workspace scoping after mode migration CWE-285 2.0 Low 2026-05-28
CVE-2026-48116 AnythingLLM: RCE via ripgrep --pre argument injection in filesystem-search-files agent skill CWE-77 7.5 High 2026-05-28
CVE-2026-45403 AnythingLLM: filesystem-copy-file follows nested symlinks and copies files from outside the allowed directory CWE-59 2.0 Low 2026-05-28
CVE-2026-42456 AnythingLLM: Cross-User TTS Audio Disclosure via Chat ID (IDOR) CWE-200 4.3 Medium 2026-05-08
CVE-2026-41318 AnythingLLM vulnerable to stored DOM XSS in chart caption renderer - LLM-driven prompt injection produces executable HTML via unsanitized renderMarkdown(content.caption) in Chartable component CWE-79 5.4 Medium 2026-04-24
CVE-2026-32719 AnythingLLM has a Zip Slip Path Traversal and Code Execution via Community Hub Plugin Import CWE-22 4.2 Medium 2026-03-13
CVE-2026-32717 AnythingLLM access control bypass: suspended users can continue using Browser Extension API keys CWE-863 2.7 Low 2026-03-13
CVE-2026-32715 AnythingLLM Manager Privilege Bypass Allows Access to Admin-Only System Preferences CWE-863 3.8 Low 2026-03-13
CVE-2026-32628 AnythingLLM has SQL Injection in Built-in SQL Agent Plugin via Unsanitized table_name Parameter CWE-89 8.8 - 2026-03-13
CVE-2026-32626 AnythingLLM has a Streaming Phase XSS to RCE via LLM Response Injection CWE-79 9.7 Critical 2026-03-13
CVE-2026-32617 AnythingLLM Permissable CORS policy CWE-942 7.1 High 2026-03-13
CVE-2026-24478 AnythingLLM vulnerable to Path Traversal CWE-22 7.2 High 2026-01-26
CVE-2026-24477 AnythingLLM has key leak in `systemSettings.js` CWE-201 9.1AI Critical AI 2026-01-26
CVE-2026-21484 AnythingLLM Vulnerable to Username Enumeration w/ Password Recovery CWE-203 5.3 Medium 2026-01-03
CVE-2024-22422 Unauthenticated Denial of Service (DOS) attack in AnythingLLM CWE-754 7.5 High 2024-01-19

All 19 known CVE vulnerabilities affecting anything-llm with full Chinese analysis, references, and POCs where available.