Zip Slip Vulnerability in AnythingLLM Application by Mintplex Labs
CVE-2026-32719

4.2MEDIUM

Key Information:

Vendor
CVE Published:
13 March 2026

What is CVE-2026-32719?

The AnythingLLM application, developed by Mintplex Labs, suffers from a security vulnerability in versions 1.11.1 and earlier. The issue arises in the function ImportedPlugin.importCommunityItemFromUrl(), where a ZIP file download from a community hub URL is processed without proper validation of the file paths contained within the archive. This oversight enables attackers to exploit a Zip Slip path traversal vulnerability, potentially leading to arbitrary code execution in the environment where AnythingLLM is deployed.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.

Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.

Affected Version(s)

anything-llm <= 1.11.1

References

CVSS V3.1

Score:
4.2
Severity:
MEDIUM
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
High
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.