


Perceptive Security
SOC/SIEM Consultancy

AnythingLLM is an application that turns pieces of content into context that any LLM can use as references during chatting. Prior to 1.13.0, the filesystem-sear…
Published:
27 mei 2026 om 22:00:00
Alert date:
28 mei 2026 om 23:02:47
Source:
nvd.nist.gov
Web Technologies, Enterprise Applications
AnythingLLM versions prior to 1.13.0 contain a command injection vulnerability in the filesystem-search-files agent skill. The vulnerability occurs when the LLM-controlled pattern parameter is passed to ripgrep without proper argument separation, allowing attackers to execute arbitrary commands. An attacker who can chat with an agent on a deployment with the filesystem plugin enabled can exploit this vulnerability by crafting malicious patterns that turn ripgrep into a script executor. Combined with the filesystem-write-text-file skill, this allows arbitrary command execution inside the AnythingLLM server container. The vulnerability affects the default Docker image configuration and has been fixed in version 1.13.0.
Technical details
Mitigation steps:
Affected products:
AnythingLLM
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-48116
https://github.com/Mintplex-Labs/anything-llm/commit/94ed62d320df1a06c229e4bc3ee09c2cb5111b33
https://github.com/Mintplex-Labs/anything-llm/security/advisories/GHSA-6hrp-7mw6-8v59
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
