Vulnerability Description
AnythingLLM is an application that turns pieces of content into context that any LLM can use as references during chatting. Prior to 1.13.0, the filesystem-search-files agent skill passes its LLM-controlled pattern parameter to ripgrep as a positional argument without a -- end-of-options separator. ripgrep parses any argument that starts with - as an option, so a pattern of --pre=/bin/sh turns ripgrep into a script executor: it runs /bin/sh <file> for every file it walks. An attacker who can chat with an agent on a deployment with the filesystem plugin enabled (the default in the official Docker image) can use this, together with the sibling filesystem-write-text-file skill, to run arbitrary commands inside the AnythingLLM server container. This vulnerability is fixed in 1.13.0.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Mintplexlabs | Anythingllm | < 1.13.0 |
Related Weaknesses (CWE)
References
- https://github.com/Mintplex-Labs/anything-llm/commit/94ed62d320df1a06c229e4bc3eePatch
- https://github.com/Mintplex-Labs/anything-llm/security/advisories/GHSA-6hrp-7mw6ExploitMitigationVendor Advisory
- https://github.com/Mintplex-Labs/anything-llm/security/advisories/GHSA-6hrp-7mw6ExploitMitigationVendor Advisory
FAQ
What is CVE-2026-48116?
CVE-2026-48116 is a vulnerability with a CVSS score of 7.5 (HIGH). AnythingLLM is an application that turns pieces of content into context that any LLM can use as references during chatting. Prior to 1.13.0, the filesystem-search-files agent skill passes its LLM-cont...
How severe is CVE-2026-48116?
CVE-2026-48116 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-48116?
Check the references section above for vendor advisories and patch information. Affected products include: Mintplexlabs Anythingllm.