AnythingLLM is an application that turns pieces of content into context that any LLM can use as references during chatting. In 1.11.1 and earlier, The ImportedPlugin.importCommunityItemFromUrl() function in server/utils/agents/imported.js downloads a ZIP file from a community hub URL and extracts it using AdmZip.extractAllTo() without validating file paths within the archive. This enables a Zip Slip path traversal attack that can lead to arbitrary code execution.
References
| Link | Resource |
|---|---|
| https://github.com/Mintplex-Labs/anything-llm/commit/6a492f038da195a5c9a239d5ca2e9f2151c25f8c | Patch |
| https://github.com/Mintplex-Labs/anything-llm/security/advisories/GHSA-rh66-4w74-cf4m | Exploit Vendor Advisory Mitigation |
Configurations
History
16 Mar 2026, 20:29
| Type | Values Removed | Values Added |
|---|---|---|
| First Time |
Mintplexlabs
Mintplexlabs anythingllm |
|
| CPE | cpe:2.3:a:mintplexlabs:anythingllm:*:*:*:*:*:*:*:* | |
| References | () https://github.com/Mintplex-Labs/anything-llm/commit/6a492f038da195a5c9a239d5ca2e9f2151c25f8c - Patch | |
| References | () https://github.com/Mintplex-Labs/anything-llm/security/advisories/GHSA-rh66-4w74-cf4m - Exploit, Vendor Advisory, Mitigation |
16 Mar 2026, 14:19
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-03-16 14:19
Updated : 2026-03-16 20:29
NVD link : CVE-2026-32719
Mitre link : CVE-2026-32719
CVE.ORG link : CVE-2026-32719
JSON object : View
Products Affected
mintplexlabs
- anythingllm
