PT-2026-25382 · Unknown+1 · Mysql Server+3

Aviral2642

·

Publicado

2026-03-13

·

Atualizado

2026-03-26

·

CVE-2026-32628

CVSS v2.0

9.0

Alta

VetorAV:N/AC:L/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions AnythingLLM versions 1.11.1 and earlier
Description AnythingLLM is an application designed to provide context from content pieces for use with Large Language Models (LLMs). A SQL injection issue exists within the built-in SQL Agent plugin. This allows users who can invoke the agent to execute arbitrary SQL commands on connected databases. The getTableSchemaSql() method in the MySQL, PostgreSQL, and MSSQL database connectors constructs SQL queries by directly concatenating the table name parameter without proper sanitization or parameterization.
Recommendations Versions prior to 1.11.1 should be updated.

Exploit

Correção

SQL injection

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2026-04255
CVE-2026-32628
GHSA-JWJX-MW2P-5WC7

Produtos afetados

Anything-Llm
Mssql
Mysql Server
Postgresql