PT-2026-25382 · Unknown+1 · Mysql Server+3
Aviral2642
·
Publicado
2026-03-13
·
Atualizado
2026-03-26
·
CVE-2026-32628
CVSS v2.0
9.0
Alta
| Vetor | AV:N/AC:L/Au:S/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
AnythingLLM versions 1.11.1 and earlier
Description
AnythingLLM is an application designed to provide context from content pieces for use with Large Language Models (LLMs). A SQL injection issue exists within the built-in SQL Agent plugin. This allows users who can invoke the agent to execute arbitrary SQL commands on connected databases. The
getTableSchemaSql() method in the MySQL, PostgreSQL, and MSSQL database connectors constructs SQL queries by directly concatenating the table name parameter without proper sanitization or parameterization.Recommendations
Versions prior to 1.11.1 should be updated.
Exploit
Correção
SQL injection
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Anything-Llm
Mssql
Mysql Server
Postgresql