Anythingllm CVE Vulnerabilities
By Mintplexlabs — 2 known vulnerabilities
Critical
0
High
1
Medium
1
Low
0
None
0
All Anythingllm CVEs
CVE-2026-48116
7.5
high
AnythingLLM is an application that turns pieces of content into context that any LLM can use as references during chatting. Prior to 1.13.0, the filesystem-search-files agent skill passes its LLM-controlled pattern parameter to ripgrep as a positional argument without a -- end-of-options separator.
May 28, 2026
CVE-2025-63390
5.3
medium
An authentication bypass vulnerability exists in AnythingLLM v1.8.5 in via the /api/workspaces endpoint. The endpoint fails to implement proper authentication checks, allowing unauthenticated remote attackers to enumerate and retrieve detailed information about all configured workspaces. Exposed dat
Dec 18, 2025