CVE-2026-48789: AnythingLLM is an application that turns pieces of content into context that any LLM can use as references during chatting. Prior to 1.13.0, on Windows, the document folder listing route can accept...

Added to the CISA Known Exploited Vulnerabilities catalog on 24 Jun 2026. Vendor: AI/ML. Product: LLM. CVSS score: 4.3.

AnythingLLM is an application that turns pieces of content into context that any LLM can use as references during chatting. Prior to 1.13.0, on Windows, the document folder listing route can accept an encoded absolute Windows path that resolves outside the intended documents directory. The shared...

Required action: Review and patch if applicable to your AI infrastructure.