PT-2026-25382 · Unknown+1 · Mysql Server+3

Aviral2642

·

Published

2026-03-13

·

Updated

2026-03-26

·

CVE-2026-32628

CVSS v2.0

9.0

High

VectorAV:N/AC:L/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions AnythingLLM versions 1.11.1 and earlier
Description AnythingLLM is an application designed to provide context from content pieces for use with Large Language Models (LLMs). A SQL injection issue exists within the built-in SQL Agent plugin. This allows users who can invoke the agent to execute arbitrary SQL commands on connected databases. The getTableSchemaSql() method in the MySQL, PostgreSQL, and MSSQL database connectors constructs SQL queries by directly concatenating the table name parameter without proper sanitization or parameterization.
Recommendations Versions prior to 1.11.1 should be updated.

Exploit

Fix

SQL injection

Weakness Enumeration

Related Identifiers

BDU:2026-04255
CVE-2026-32628
GHSA-JWJX-MW2P-5WC7

Affected Products

Anything-Llm
Mssql
Mysql Server
Postgresql