CVE 7.2 HIGH

AnythingLLM vulnerable to Path Traversal_CVE-2026-24478

7.2 / 10
HIGH
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

Description

AnythingLLM is an application that turns pieces of content into context that any LLM can use as references during chatting. Prior to version 1.10.0, a critical Path Traversal vulnerability in the DrupalWiki integration allows a malicious admin (or an attacker who can convince an admin to configure a malicious DrupalWiki URL) to write arbitrary files to the server. This can lead to Remote Code Execution (RCE) by overwriting configuration files or writing executable scripts. Version 1.10.0 fixes the issue.

Basic Information

ID CVE-2026-24478
Source GitHub_M
Published Jan 26, 2026 at 23:23

Affected Product

Vendor Mintplex-Labs
Product anything-llm
Version < 1.10.0
Affected Versions Mintplex-Labs anything-llm < 1.10.0

CWE Classification

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.