PT-2026-25382 · Unknown+1 · Mysql Server+3
Aviral2642
·
Published
2026-03-13
·
Updated
2026-03-26
·
CVE-2026-32628
CVSS v2.0
9.0
High
| Vector | AV:N/AC:L/Au:S/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
AnythingLLM versions 1.11.1 and earlier
Description
AnythingLLM is an application designed to provide context from content pieces for use with Large Language Models (LLMs). A SQL injection issue exists within the built-in SQL Agent plugin. This allows users who can invoke the agent to execute arbitrary SQL commands on connected databases. The
getTableSchemaSql() method in the MySQL, PostgreSQL, and MSSQL database connectors constructs SQL queries by directly concatenating the table name parameter without proper sanitization or parameterization.Recommendations
Versions prior to 1.11.1 should be updated.
Exploit
Fix
SQL injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Anything-Llm
Mssql
Mysql Server
Postgresql