PT-2026-4837 · Unknown · Drupal Wiki+1

Ylchen-007

·

Publicado

2026-01-26

·

Atualizado

2026-01-27

·

CVE-2026-24478

CVSS v3.1

7.2

Alta

VetorAV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions AnythingLLM versions prior to 1.10.0
Description AnythingLLM is an application that turns content into context for Large Language Models (LLMs). A critical Path Traversal issue exists in the DrupalWiki integration for versions prior to 1.10.0. This allows a malicious administrator, or an attacker who can manipulate an administrator into configuring a malicious DrupalWiki URL, to write arbitrary files to the server. This could lead to Remote Code Execution (RCE) through overwriting configuration files or writing executable scripts. The API endpoint involved is not explicitly mentioned. The vulnerable parameter is the DrupalWiki URL configured by the administrator, drupal wiki url.
Recommendations Versions prior to 1.10.0 should be updated to version 1.10.0 or later.

Exploit

Correção

RCE

Path traversal

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2026-24478
GHSA-JP2F-99H9-7VJV

Produtos afetados

Anything-Llm
Drupal Wiki