AnythingLLM is an application that turns pieces of content into context that any LLM can use as references during chatting. In 1.11.1 and earlier, The ImportedPlugin.importCommunityItemFromUrl() function in server/utils/agents/imported.js downloads a ZIP file from a community hub URL and extracts it using AdmZip.extractAllTo() without validating file paths within the archive. This enables a Zip Slip path traversal attack that can lead to arbitrary code execution.
References
| Link | Resource |
|---|---|
| https://github.com/Mintplex-Labs/anything-llm/commit/6a492f038da195a5c9a239d5ca2e9f2151c25f8c | Patch |
| https://github.com/Mintplex-Labs/anything-llm/security/advisories/GHSA-rh66-4w74-cf4m | Exploit Vendor Advisory Mitigation |
Configurations
History
No history.
Information
Published : 2026-03-16 14:19
Updated : 2026-03-16 20:29
NVD link : CVE-2026-32719
Mitre link : CVE-2026-32719
CVE.ORG link : CVE-2026-32719
JSON object : View
Products Affected
mintplexlabs
- anythingllm
