SQL Injection Vulnerability in AnythingLLM Application by Mintplex Labs
CVE-2026-32628
What is CVE-2026-32628?
The AnythingLLM application, utilized for transforming content into usable context for various language models, is susceptible to a SQL injection flaw that allows any user with access to the built-in SQL Agent plugin to execute arbitrary SQL commands on associated databases. This vulnerability arises from the getTableSchemaSql() method within all three database connectors—MySQL, PostgreSQL, and MSSQL—where SQL queries are formed through direct string concatenation of the user-supplied table_name parameter, devoid of necessary sanitization or parameterization, potentially leading to severe security risks.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
anything-llm <= 1.11.1
