CVE-2026-45403: AnythingLLM is an application that turns pieces of content into context that any LLM can use as references during chatting. Prior to 1.13.0, the AnythingLLM agent filesystem copy tool validates onl...
Added to the CISA Known Exploited Vulnerabilities catalog on 28 May 2026. Vendor: AI/ML. Product: LLM. CVSS score: 2.
AnythingLLM is an application that turns pieces of content into context that any LLM can use as references during chatting. Prior to 1.13.0, the AnythingLLM agent filesystem copy tool validates only the top-level source and destination paths. The recursive copy helper then descends into child ent...
Required action: Review and patch if applicable to your AI infrastructure.