Description
AnythingLLM is an application that turns pieces of content into context that any LLM can use as references during chatting. In 1.16.1 and earlier, the manager role can store meta_page_title or meta_page_favicon through /api/admin/system-preferences, and MetaGenerator inserts those values into production homepage HTML without escaping attribute values or text content. The values pass unchanged through server/models/systemSettings.js and reach MetaGenerator.generate() in server/index.js. #assembleMeta() in server/utils/boot/MetaGenerator.js concatenates the stored values into HTML. When an administrator visits the homepage /, injected JavaScript can read the administrator JWT and use it to create API keys, access or modify workspace and chat data, delete users, and perform other administrator actions. server/endpoints/admin.js accepts the manager-controlled settings before server/models/systemSettings.js returns them unchanged. No fixed version is available as of this review.
Published: 2026-09-10
Score: 5.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Stored XSS leading to Privilege Escalation
Action: Restrict Access
AI Analysis

Impact

AnythingLLM allows a manager to store meta_page_title or meta_page_favicon via the system‑preferences API. Those values are later concatenated into the homepage HTML without applying any escaping, creating a stored XSS flaw. When an administrator visits the homepage, the injected JavaScript can read the administrator’s JWT and use it to create API keys, access or modify workspace data, delete users, or perform other privileged actions. The weakness is an input manipulation flaw (CWE‑79) that directly threatens the confidentiality and integrity of administrative sessions.

Affected Systems

Mintplex‑Labs AnythingLLM versions 1.16.1 and earlier are affected. The vulnerability is present in all releases up to and including 1.16.1 and no fixed version is currently available.

Risk and Exploitability

The CVSS score of 5.5 denotes moderate severity. No EPSS score is available, and the vulnerability is not listed in the CISA KEV catalog, indicating a low publicly available exploitation probability. The flaw requires manager privileges. Once malicious content is embedded in the homepage, a logged‑in administrator can execute it, providing an attacker with the session JWT and enabling privilege escalation.

Generated by OpenCVE AI on September 11, 2026 at 00:05 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Sanitize or escape meta_page_title and meta_page_favicon values when rendering the homepage HTML to prevent injection
  • Implement a strict Content Security Policy that disallows inline scripts and eval to reduce the impact of potential XSS
  • Restrict write access to system preferences to a minimal set of trusted administrators and audit changes to these settings

Generated by OpenCVE AI on September 11, 2026 at 00:05 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 11 Sep 2026 08:30:00 +0000

Type Values Removed Values Added
First Time appeared Mintplexlabs
Mintplexlabs anything-llm
Vendors & Products Mintplexlabs
Mintplexlabs anything-llm

Thu, 10 Sep 2026 19:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 10 Sep 2026 18:00:00 +0000

Type Values Removed Values Added
Description AnythingLLM is an application that turns pieces of content into context that any LLM can use as references during chatting. In 1.16.1 and earlier, the manager role can store meta_page_title or meta_page_favicon through /api/admin/system-preferences, and MetaGenerator inserts those values into production homepage HTML without escaping attribute values or text content. The values pass unchanged through server/models/systemSettings.js and reach MetaGenerator.generate() in server/index.js. #assembleMeta() in server/utils/boot/MetaGenerator.js concatenates the stored values into HTML. When an administrator visits the homepage /, injected JavaScript can read the administrator JWT and use it to create API keys, access or modify workspace and chat data, delete users, and perform other administrator actions. server/endpoints/admin.js accepts the manager-controlled settings before server/models/systemSettings.js returns them unchanged. No fixed version is available as of this review.
Title AnythingLLM: Stored XSS Due to Unescaped Server-Side HTML Concatenation in MetaGenerator
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 5.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:L/I:L/A:N'}


Subscriptions

Mintplexlabs Anything-llm
cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-09-10T18:15:36.256Z

Reserved: 2026-09-09T21:22:45.434Z

Link: CVE-2026-88055

cve-icon Vulnrichment

Updated: 2026-09-10T18:15:32.799Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-10T18:18:14.743

Modified: 2026-09-10T19:54:25.810

Link: CVE-2026-88055

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-11T08:15:15Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')