CVE-2026-32628Disclosure(mintplexlabs / anythingllm)

LOWCVSS 8.8 · HIGH

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

AnythingLLM is an application that turns pieces of content into context that any LLM can use as references during chatting. In 1.11.1 and earlier, a SQL injection vulnerability in the built-in SQL Agent plugin allows any user who can invoke the agent to execute arbitrary SQL commands on connected databases. The getTableSchemaSql() method in all three database connectors (MySQL, PostgreSQL, MSSQL) constructs SQL queries using direct string concatenation of the table_name parameter without sanitization or parameterization.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-89

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • anythingllm

Threat summary

  • 3 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 3 signals
  • Disclosure: 3 classified signals
  • Peaked at 2 mentions on most recent observed day (2026-03-26)
  • 3 total mentions across 2 days

Affected systems

Products
anythingllm

Deep dive

Activity timeline3 mentions / 2d
01122Mentions · 2026-03-13: 1Mentions · 2026-03-26: 2Technical Details · 2026-03-13: 1Technical Details · 2026-03-26: 203-1303-26
Signal classification1 categories
Disclosure
3100.0%
Referenced assets2 URLs
Classification over time
DateTotalLabels
2026-03-131
Disclosure1
2026-03-262
Disclosure2
Full discourse3 posts
  • HackerNoon | Learn Any Technology@hackernoon
    Disclosure

    CVE-2026-32628 is a high-severity SQL injection in AnythingLLM's built-in SQL Agent affecting MySQL, PostgreSQL, and MSSQL connectors. - https://hackernoon.com/a-56000-star-ai-app-shipped-with-a-textbook-sql-injection-flaw #cybersecurity #aisecurity

    Post summary

    The post announces CVE‑2026‑32628 as a high‑severity SQL injection in AnythingLLM's SQL Agent for multiple database connectors, but does not provide PoC code, exploit methodology, or patch information.

    01012268
    91.1K followersView on X
  • Dar Fazulyanov@DarFazulyanov
    Disclosure

    Same week: AnythingLLM (56K GitHub stars) shipped with a textbook SQL injection in its SQL Agent. CVE-2026-32628. MySQL, PostgreSQL, MSSQL all affected. The agent had direct DB access. The flaw let attackers execute arbitrary SQL through it.

    Post summary

    The post announces CVE-2026-32628, a textbook SQL injection flaw in AnythingLLM's SQL Agent that permits arbitrary SQL execution on MySQL, PostgreSQL, and MSSQL, with no mention of exploits, patches, or active attacks.

    1000048
    295 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-32628 AnythingLLM is an application that turns pieces of content into context that any LLM can use as references during chatting. In 1.11.1 and earlier, a SQL injection vul… https://www.cve.org/CVERecord?id=CVE-2026-32628

    Post summary

    The tweet announces CVE-2026-32628 as a SQL injection vulnerability affecting AnythingLLM 1.11.1 and earlier, linking to the official CVE record but providing no PoC, exploit, or patch details.

    00000139
    56.7K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appmintplexlabsanythingllm---

Explore more