PT-2026-4837 · Unknown · Drupal Wiki+1
Ylchen-007
·
Published
2026-01-26
·
Updated
2026-01-27
·
CVE-2026-24478
CVSS v3.1
7.2
High
| Vector | AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
AnythingLLM versions prior to 1.10.0
Description
AnythingLLM is an application that turns content into context for Large Language Models (LLMs). A critical Path Traversal issue exists in the DrupalWiki integration for versions prior to 1.10.0. This allows a malicious administrator, or an attacker who can manipulate an administrator into configuring a malicious DrupalWiki URL, to write arbitrary files to the server. This could lead to Remote Code Execution (RCE) through overwriting configuration files or writing executable scripts. The API endpoint involved is not explicitly mentioned. The vulnerable parameter is the DrupalWiki URL configured by the administrator,
drupal wiki url.Recommendations
Versions prior to 1.10.0 should be updated to version 1.10.0 or later.
Exploit
Fix
RCE
Path traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Anything-Llm
Drupal Wiki