AnythingLLM stored XSS via unsanitised chart captions (CVE-2026-41318)
AnythingLLM versions prior to 1.12.1 rendered chart captions from LLM output through a markdown renderer without DOMPurify sanitisation, allowing stored DOM-level XSS. An attacker who could influence the model's output, typically via indirect prompt injection in a shared workspace document, could execute script in other users' browsers when they opened the conversation.
Disclosed 24 April 2026 · Record updated 13 September 2026
Impact
Stored cross-site scripting executing in the browsers of other users of a shared multi-user workspace when they view the affected conversation.
Our coverage
No articles linked to this incident yet.
Sources
- nvd.nist.govhttps://nvd.nist.gov/vuln/detail/CVE-2026-41318
