AnythingLLM agent filesystem skills allow command execution and path escape
Two vulnerabilities in AnythingLLM prior to 1.13.0 let an attacker chatting with an agent abuse the filesystem skills: an LLM-controlled ripgrep pattern (--pre=/bin/sh) enabled arbitrary command execution inside the server container, and the copy tool followed nested symlinks to copy files from outside the allowed filesystem root. Both were fixed in version 1.13.0.
Disclosed 28 May 2026 · Record updated 13 September 2026
Impact
Attackers able to chat with an agent on a deployment with the filesystem plugin enabled (default in the official Docker image) could run arbitrary commands in the AnythingLLM server container and copy files from outside the permitted filesystem root.
Our coverage
No articles linked to this incident yet.
Sources
- nvd.nist.govhttps://nvd.nist.gov/vuln/detail/CVE-2026-45403
- nvd.nist.govhttps://nvd.nist.gov/vuln/detail/CVE-2026-48116
