
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-5627 is a path traversal vulnerability in the AgentFlows component of mintplex-labs/anything-llm, affecting versions up to and including 1.9.1. The flaw allows authenticated high-privilege attackers to bypass directory restrictions and access or delete arbitrary .json files on the server. It was published on April 7, 2026, and resolved in version 1.12.1. The NVD assigns a CVSS v3.1 base score of 7.2 (High), while the GitHub Advisory Database rates it 9.1 (Critical) using a scope-changed vector (Github Advisory, Feedly).
The vulnerability is classified as CWE-29 (Path Traversal: '\..\filename') and stems from improper input validation in the loadFlow and deleteFlow methods within server/utils/agentFlows/index.js. The flawed logic combines path.join with normalizePath without subsequently verifying that the resolved path remains within the intended AgentFlows.flowsDir directory, allowing traversal sequences to escape the restricted folder. The fix, committed in 3444b9b, introduces an isWithin() boundary check in loadFlow, saveFlow, and deleteFlow to ensure all resolved paths stay within the designated flows directory. Exploitation requires network access and high-privilege (admin) authentication (Github Advisory, Patch Commit).
A successful exploit allows an authenticated admin-level attacker to read arbitrary .json files outside the intended directory, potentially exposing sensitive configuration files containing API keys and credentials (confidentiality impact). The attacker can also delete critical .json files such as package.json, causing service disruption or denial of service (availability impact). While the scope is limited to .json files, the exposure of API keys could enable further lateral movement or compromise of integrated external services (Github Advisory, Feedly).
No confirmed in-the-wild exploitation has been observed, and no functional proof-of-concept exploit code is publicly available as of the time of reporting. A bounty report exists on Huntr (Huntr Bounty), but its content was found to be non-exploitable upon analysis. The EPSS score is approximately 0.033–0.063%, indicating a low near-term exploitation probability. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog, and no threat actor attribution has been reported (Feedly, Github Advisory).
.json files outside the AgentFlows.flowsDir, such as configuration files containing API keys or package.json.../../config/settings) that, when processed by path.join and normalizePath, resolves to a path outside the intended flows directory.loadFlow: Send an authenticated API request to the loadFlow endpoint with the crafted UUID to read the contents of the targeted .json file, disclosing sensitive configuration data.deleteFlow: Alternatively, send an authenticated API request to the deleteFlow endpoint with the traversal payload to delete a critical .json file (e.g., package.json), causing a denial of service (Github Advisory, Patch Commit)./api/agent-flows/load or /api/agent-flows/delete) containing UUID parameters with path traversal sequences such as ../, ..\, or encoded variants (%2e%2e%2f)..json files outside the AgentFlows.flowsDir directory; missing or deleted package.json or other critical configuration files..json files, potentially indicating a denial-of-service attempt (Github Advisory, Patch Commit).The primary remediation is to upgrade anything-llm to version 1.12.1 or later, which introduces isWithin() boundary checks in the loadFlow, saveFlow, and deleteFlow methods to prevent directory traversal (Patch Commit). As a temporary workaround, restrict admin access to trusted users only and apply network-level controls to limit access to the anything-llm server. Additionally, implement strict input validation on UUID parameters and ensure the application runs with the least-privilege file system permissions to limit the impact of any traversal attempt (Github Advisory).
The vulnerability was reported through the Huntr bug bounty platform and disclosed publicly on April 7, 2026. A brief mention appeared on Bluesky via the CVE tracking account, and several vulnerability aggregation sites (VulDB, cvefeed.io, thehackerwire.com) picked up the disclosure shortly after publication. No significant vendor statements beyond the patch commit or notable researcher commentary beyond the Huntr bounty report have been identified (Huntr Bounty, Github Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."