PT-2026-25398 · Admzip+1 · Adm-Zip+1
Timothycarambat
·
Publicado
2026-03-13
·
Atualizado
2026-03-16
·
CVE-2026-32719
CVSS v2.0
6.8
Média
| Vetor | AV:N/AC:H/Au:M/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
AnythingLLM versions 1.11.1 and earlier
Description
AnythingLLM is an application designed to provide context for Large Language Models (LLMs). The
ImportedPlugin.importCommunityItemFromUrl() function, located in server/utils/agents/imported.js, downloads ZIP files from community hub URLs and extracts their contents using AdmZip.extractAllTo(). A lack of validation for file paths within the archive allows for a Zip Slip path traversal attack, potentially leading to arbitrary code execution.Recommendations
Versions prior to 1.11.1 should be updated. As a temporary workaround, consider restricting the use of the
importCommunityItemFromUrl() function until a patch is available.Exploit
Correção
Code Injection
Path traversal
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Adm-Zip
Anything-Llm