PT-2026-25398 · Admzip+1 · Adm-Zip+1

Timothycarambat

·

Publicado

2026-03-13

·

Atualizado

2026-03-16

·

CVE-2026-32719

CVSS v2.0

6.8

Média

VetorAV:N/AC:H/Au:M/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions AnythingLLM versions 1.11.1 and earlier
Description AnythingLLM is an application designed to provide context for Large Language Models (LLMs). The ImportedPlugin.importCommunityItemFromUrl() function, located in server/utils/agents/imported.js, downloads ZIP files from community hub URLs and extracts their contents using AdmZip.extractAllTo(). A lack of validation for file paths within the archive allows for a Zip Slip path traversal attack, potentially leading to arbitrary code execution.
Recommendations Versions prior to 1.11.1 should be updated. As a temporary workaround, consider restricting the use of the importCommunityItemFromUrl() function until a patch is available.

Exploit

Correção

Code Injection

Path traversal

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2026-04254
CVE-2026-32719
GHSA-RH66-4W74-CF4M

Produtos afetados

Adm-Zip
Anything-Llm