Vulnerability  ·  2026-06-25

AnythingLLM Windows Path Traversal — Encoded Absolute Path Escapes Documents Directory (CVSS 4.3)

VulnerabilityMedium impactGlobalCVE-2026-48789
The document folder listing route in AnythingLLM on Windows accepts an encoded absolute path parameter that, after URL decoding and shared path normalization, resolves outside the intended documents directory. Authenticated users can enumerate arbitrary filesystem paths on the Windows host.
AnythingLLM is a self-hosted RAG application that turns documents into LLM context. Filesystem enumeration by an authenticated user can reveal sensitive files accessible to the AnythingLLM process, including configuration files containing API keys and database credentials used by the AI deployment.
Authenticated attacker sends a document folder listing request with an encoded absolute Windows path that resolves outside the intended documents directory, returning a listing of arbitrary filesystem locations
AnythingLLM < 1.13.0 (Windows only)
Upgrade to AnythingLLM 1.13.0. Advisory: https://github.com/Mintplex-Labs/anything-llm/security/advisories/GHSA-j4m9-wwcq-m868
Sources
NVD CVE-2026-48789GitHub Security Advisory GHSA-j4m9-wwcq-m868
See this in the live feed Explore related AI security and governance findings — updated every morning.
Open the feed →