CVE-2026-32626 is a critical Remote Code Execution (RCE) vulnerability impacting AnythingLLM Desktop versions 1.11.1 and earlier. This flaw, rated 9.6 CVSS, arises from a Streaming Phase XSS in the chat rendering pipeline that escalates to RCE due to insecure Electron configuration, allowing full host compromise with low attack complexity and requiring only normal chat usage. Although not currently listed on the KEV catalog and lacking public exploit code, it is designated as an "Active" threat on the Hot List and has received notable community discussion.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 1.11.1CPE matchmatch criteria | cpe:2.3:a:mintplexlabs:anythingllm:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.8 Bluesky, 0.5 Mastodon, and 1.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.1 Security Researcher mentions.
Remediation records are not available for this CVE.