CVE-2026-32626Disclosure(mintplexlabs / anythingllm)

LOWCVSS 9.6 · CRITICAL

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Patch mintplexlabs anythingllm systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

AnythingLLM is an application that turns pieces of content into context that any LLM can use as references during chatting. In 1.11.1 and earlier, AnythingLLM Desktop contains a Streaming Phase XSS vulnerability in the chat rendering pipeline that escalates to Remote Code Execution on the host OS due to insecure Electron configuration. This works with default settings and requires no user interaction beyond normal chat usage. The custom markdown-it image renderer in frontend/src/utils/chat/markdown.js interpolates token.content directly into the alt attribute without HTML entity escaping. The PromptReply component renders this output via dangerouslySetInnerHTML without DOMPurify sanitization — unlike HistoricalMessage which correctly applies DOMPurify.sanitize().

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-79

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • anythingllm

Threat summary

  • Patch or workaround signal is available
  • 5 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 4 signals
  • Disclosure: 3 classified signals
  • General: 1 classified signal
  • Peaked 2d ago at 2 mentions (2026-03-13); latest day: 2
  • 5 total mentions across 3 days

Affected systems

Products
anythingllm

Deep dive

Activity timeline5 mentions / 3d
01122Mentions · 2026-03-13: 2Mentions · 2026-03-16: 1Mentions · 2026-03-22: 2Patch / Workaround · 2026-03-22: 1Technical Details · 2026-03-13: 1Technical Details · 2026-03-16: 1Technical Details · 2026-03-22: 203-1303-1603-22
Signal classification3 categories
Disclosure
360.0%
General
120.0%
Patch
120.0%
Referenced assets5 URLs
Classification over time
DateTotalLabels
2026-03-132
Disclosure1General1
2026-03-161
Disclosure1
2026-03-222
Disclosure1Patch1
Full discourse5 posts
  • Nicolas Krassas@Dinosn
    Patch

    Critical: AnythingLLM Desktop XSS-to-RCE via insecure Electron config. Poisoned RAG documents or compromised LLM endpoints can achieve full host compromise. CVE-2026-32626, CVSS 9.6. Patch available. https://raxe.ai/labs/advisories/RAXE-2026-038

    Post summary

    The advisory discloses a critical XSS‑to‑RCE flaw in AnythingLLM Desktop (CVE‑2026‑32626) with CVSS 9.6 and confirms a patch is available.

    110033102.8K
    153.4K followersView on X
  • VulnTracker@vuln_tracker
    Disclosure

    CVE-2026-32626 is a perfect example of why AI tooling is becoming prime attack surface. Poisoned documents in your RAG pipeline achieving full host compromise through Electron misconfig - attackers don't need to break the model, just feed it. Monitor AI CVEs: https://vulntracker.io

    Post summary

    The post announces CVE‑2026‑32626 as a new vulnerability that enables attackers to compromise hosts via Electron misconfiguration by feeding poisoned documents into AI pipelines, but it gives no PoC, exploit, or patch details and does not confirm active exploitation.

    0001070
    445 followersView on X
  • CVEFind.com@CveFindCom
    Disclosure

    [CVE-2026-32626: CRITICAL] AnythingLLM application poses a serious cyber threat due to an XSS vulnerability enabling Remote Code Execution. The flaw in the Electron configuration allows exploitation through ...#cve,CVE-2026-32626,#cybersecurity https://cvefind.com/CVE-2026-32626

    Post summary

    The post highlights CVE-2026-32626 as a critical XSS‑to‑RCE flaw in AnythingLLM, but offers no PoC, exploit code, patch information, or evidence of active exploitation.

    0000052
    601 followersView on X
  • CVE@CVEnew
    General

    CVE-2026-32626 AnythingLLM is an application that turns pieces of content into context that any LLM can use as references during chatting. In 1.11.1 and earlier, AnythingLLM Desktop… https://www.cve.org/CVERecord?id=CVE-2026-32626

    Post summary

    The article merely references CVE-2026-32626 in relation to AnythingLLM, with no further technical, exploit or mitigation details.

    00000164
    56.7K followersView on X
  • 0day Signal@0dayPublishing
    Disclosure

    🚨 CVE-2026-32626: AnythingLLM has a Streaming Phas... LLM response injection bypasses DOMPurify in PromptReply component, weaponizing markdown-it's unescaped alt attributes ... https://zerodaysignal.com/vulnerability/CVE-2026-32626 #netsec #vulnerability #CVE #sysadmin #zeroday

    Post summary

    A newly disclosed CVE-2026-32626 in AnythingLLM exposes a response injection flaw bypassing DOMPurify, leveraging unescaped alt attributes in markdown‑it; no exploit code or patch details are provided.

    0000061
    147 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appmintplexlabsanythingllm---

Explore more