CVE Explorer
CVE-2026-45403
AnythingLLM is an application that turns pieces of content into context that any LLM can use as references during chatting. Prior to 1.13.0, the AnythingLLM agent filesystem copy tool validates only the top-level source and destination paths. The recursive copy helper then descends into child entries using fs.stat() and copies files with fs.copyFile() without validating each child or rejecting symlinks. Because both APIs follow symlinks, a symlink nested inside an allowed source directory can po
Known exploited
Not asserted
Disputed
No
Stale source
No
Conflicts
0
Affected products and versions
1 source assertion{"product":"anything-llm","vendor":"Mintplex-Labs","versions":[{"status":"affected","version":"< 1.13.0"}]}
- cve_program_cvelist_v5affectedurn:baitaphish:normalized-source-record:v2:4c51c3b05ed9f22fa030f2ca36ff8dd9d4de7781e3aca64a5828a80b28f1566d · sha256:6337676a7f952a56… · /containers/cna/affected/0
Provider-owned CVSS observations
1 source assertion{"metric":{"attackComplexity":"HIGH","attackVector":"NETWORK","availabilityImpact":"NONE","baseScore":2,"baseSeverity":"LOW","confidentialityImpact":"LOW","integrityImpact":"NONE","privilegesRequired":"HIGH","scope":"UNCHANGED","userInteraction":"REQUIRED","vectorString":"CVSS:3.1/AV:N/AC:H/PR:H/UI:R/S:U/C:L/I:N/A:N","version":"3.1"},"metric_type":"cvssV3_1"}
- cve_program_cvelist_v5cvssurn:baitaphish:normalized-source-record:v2:4c51c3b05ed9f22fa030f2ca36ff8dd9d4de7781e3aca64a5828a80b28f1566d · sha256:6337676a7f952a56… · /containers/cna/metrics/0/cvssV3_1
CWE assertions
1 source assertion{"cweId":"CWE-59","description":"CWE-59: Improper Link Resolution Before File Access ('Link Following')","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:4c51c3b05ed9f22fa030f2ca36ff8dd9d4de7781e3aca64a5828a80b28f1566d · sha256:6337676a7f952a56… · /containers/cna/problemTypes/0/descriptions/0
Source references
3 source assertions{"name":"https://github.com/Mintplex-Labs/anything-llm/commit/21ce03087145a4261c1de03b056fba639f699c09","tags":["x_refsource_MISC"],"url":"https://github.com/Mintplex-Labs/anything-llm/commit/21ce03087145a4261c1de03b056fba639f699c09"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:4c51c3b05ed9f22fa030f2ca36ff8dd9d4de7781e3aca64a5828a80b28f1566d · sha256:6337676a7f952a56… · /containers/cna/references/1
{"tags":["exploit"],"url":"https://github.com/Mintplex-Labs/anything-llm/security/advisories/GHSA-vjrp-43mm-j7vw"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:4c51c3b05ed9f22fa030f2ca36ff8dd9d4de7781e3aca64a5828a80b28f1566d · sha256:6337676a7f952a56… · /containers/adp/0/references/0
{"name":"https://github.com/Mintplex-Labs/anything-llm/security/advisories/GHSA-vjrp-43mm-j7vw","tags":["x_refsource_CONFIRM"],"url":"https://github.com/Mintplex-Labs/anything-llm/security/advisories/GHSA-vjrp-43mm-j7vw"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:4c51c3b05ed9f22fa030f2ca36ff8dd9d4de7781e3aca64a5828a80b28f1566d · sha256:6337676a7f952a56… · /containers/cna/references/0
Attribution and limitations
- CVE Program CVEList V5: Reproduce the MITRE copyright designation and CVE license in copies. Source →
Provider severity values are preserved separately. Baitaphish does not convert them into a risk rating, infer affected products, or treat EPSS as observed exploitation.