Impact
AnythingLLM allows a manager to store meta_page_title or meta_page_favicon via the system‑preferences API. Those values are later concatenated into the homepage HTML without applying any escaping, creating a stored XSS flaw. When an administrator visits the homepage, the injected JavaScript can read the administrator’s JWT and use it to create API keys, access or modify workspace data, delete users, or perform other privileged actions. The weakness is an input manipulation flaw (CWE‑79) that directly threatens the confidentiality and integrity of administrative sessions.
Affected Systems
Mintplex‑Labs AnythingLLM versions 1.16.1 and earlier are affected. The vulnerability is present in all releases up to and including 1.16.1 and no fixed version is currently available.
Risk and Exploitability
The CVSS score of 5.5 denotes moderate severity. No EPSS score is available, and the vulnerability is not listed in the CISA KEV catalog, indicating a low publicly available exploitation probability. The flaw requires manager privileges. Once malicious content is embedded in the homepage, a logged‑in administrator can execute it, providing an attacker with the session JWT and enabling privilege escalation.
OpenCVE Enrichment