Path Traversal Vulnerability in AnythingLLM Affecting DrupalWiki Integration
CVE-2026-24478
7.2HIGH
What is CVE-2026-24478?
The AnythingLLM application, prior to version 1.10.0, has a vulnerability associated with its DrupalWiki integration. This path traversal vulnerability allows a malicious administrative user, or an attacker who persuades an admin to set up a malicious DrupalWiki URL, to write arbitrary files to the server. This can result in Remote Code Execution (RCE), enabling the attacker to overwrite critical configuration files or deploy executable scripts, posing serious security risks to the server and its data.
Affected Version(s)
anything-llm < 1.10.0
