Vulnerability  ·  2026-09-11

AnythingLLM — stored XSS via unsanitized meta_page_title/meta_page_favicon in admin system-preferences API

VulnerabilityMedium impactGlobalCVE-2026-88055
AnythingLLM's admin system-preferences API allows a manager-role account to set page-metadata fields that are later injected unsanitized into generated HTML by MetaGenerator, producing a stored XSS vulnerability.
AnythingLLM is a popular self-hosted RAG/chat platform; while this requires manager-level privilege to exploit, it allows a malicious or compromised manager account to run arbitrary script in the browser context of any other user who loads the affected page, potentially leading to session/credential theft.
A manager-role user stores attacker-controlled meta_page_title or meta_page_favicon values via /api/admin/system-preferences; MetaGenerator inserts those values into produced pages without sufficient sanitization, resulting in stored XSS against any user who views the affected page.
AnythingLLM, versions ≤ 1.16.1
Upgrade to the patched AnythingLLM release addressing CVE-2026-88055 per the vendor commit.
GitHub commit - AnythingLLM fixNVD - CVE-2026-88055
See this in the live feed Explore related AI security and governance findings — updated every morning.
Open the feed →