Sunday, 13 September 2026
8 agent hacks today 7 vs yesterday (1)

AnythingLLM agent filesystem skills allow command execution and path escape

Two vulnerabilities in AnythingLLM prior to 1.13.0 let an attacker chatting with an agent abuse the filesystem skills: an LLM-controlled ripgrep pattern (--pre=/bin/sh) enabled arbitrary command execution inside the server container, and the copy tool followed nested symlinks to copy files from outside the allowed filesystem root. Both were fixed in version 1.13.0.

Disclosed 28 May 2026 · Record updated 13 September 2026

Impact

Attackers able to chat with an agent on a deployment with the filesystem plugin enabled (default in the official Docker image) could run arbitrary commands in the AnythingLLM server container and copy files from outside the permitted filesystem root.

Our coverage

No articles linked to this incident yet.

Sources

  1. nvd.nist.govhttps://nvd.nist.gov/vuln/detail/CVE-2026-45403
  2. nvd.nist.govhttps://nvd.nist.gov/vuln/detail/CVE-2026-48116