CVE-2026-32628 is a high-severity SQL injection vulnerability affecting AnythingLLM versions 1.11.1 and earlier, specifically within its built-in SQL Agent plugin. This flaw allows any user capable of invoking the agent to execute arbitrary SQL commands on connected databases due to unsanitized string concatenation in SQL queries. Rated CVSS 8.8 (High), the vulnerability has a network attack vector, low attack complexity, and requires only low privileges, leading to high impacts on confidentiality, integrity, and availability. While there is no evidence of active exploitation in the wild or public exploit code available, the vulnerability is on a "Hot List" and has received some community attention.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 1.11.1CPE matchmatch criteria | cpe:2.3:a:mintplexlabs:anythingllm:*:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.