


Perceptive Security
SOC/SIEM Consultancy

AnythingLLM is an application that turns pieces of content into context that any LLM can use as references during chatting. In 1.11.1 and earlier, AnythingLLM D…
Published:
15 March 2026 at 23:00:00
Alert date:
16 March 2026 at 21:03:40
Source:
nvd.nist.gov
Web Technologies, Emerging Technologies
AnythingLLM Desktop versions 1.11.1 and earlier contain a critical XSS vulnerability in the chat rendering pipeline that escalates to Remote Code Execution. The vulnerability occurs in the custom markdown-it image renderer which interpolates token.content directly into HTML alt attributes without proper escaping. The PromptReply component renders this output via dangerouslySetInnerHTML without DOMPurify sanitization, unlike the secure HistoricalMessage component. This works with default settings and requires no user interaction beyond normal chat usage, making it particularly dangerous. The insecure Electron configuration allows the XSS to escalate to full RCE on the host operating system.
Technical details
Mitigation steps:
Affected products:
AnythingLLM Desktop
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-32626
https://github.com/Mintplex-Labs/anything-llm/commit/9e2d144dc8be6fab29f560f5bcdaa9ef7dbb4214
https://github.com/Mintplex-Labs/anything-llm/security/advisories/GHSA-rrmw-2j6x-4mf2
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
