CVE-2026-5627: 
Homebrew vulnerability analysis and mitigation

Overview

CVE-2026-5627 is a path traversal vulnerability in the AgentFlows component of mintplex-labs/anything-llm, affecting versions up to and including 1.9.1. The flaw allows authenticated high-privilege attackers to bypass directory restrictions and access or delete arbitrary .json files on the server. It was published on April 7, 2026, and resolved in version 1.12.1. The NVD assigns a CVSS v3.1 base score of 7.2 (High), while the GitHub Advisory Database rates it 9.1 (Critical) using a scope-changed vector (Github Advisory, Feedly).

Technical details

The vulnerability is classified as CWE-29 (Path Traversal: '\..\filename') and stems from improper input validation in the loadFlow and deleteFlow methods within server/utils/agentFlows/index.js. The flawed logic combines path.join with normalizePath without subsequently verifying that the resolved path remains within the intended AgentFlows.flowsDir directory, allowing traversal sequences to escape the restricted folder. The fix, committed in 3444b9b, introduces an isWithin() boundary check in loadFlow, saveFlow, and deleteFlow to ensure all resolved paths stay within the designated flows directory. Exploitation requires network access and high-privilege (admin) authentication (Github Advisory, Patch Commit).

Impact

A successful exploit allows an authenticated admin-level attacker to read arbitrary .json files outside the intended directory, potentially exposing sensitive configuration files containing API keys and credentials (confidentiality impact). The attacker can also delete critical .json files such as package.json, causing service disruption or denial of service (availability impact). While the scope is limited to .json files, the exposure of API keys could enable further lateral movement or compromise of integrated external services (Github Advisory, Feedly).

Exploitability

No confirmed in-the-wild exploitation has been observed, and no functional proof-of-concept exploit code is publicly available as of the time of reporting. A bounty report exists on Huntr (Huntr Bounty), but its content was found to be non-exploitable upon analysis. The EPSS score is approximately 0.033–0.063%, indicating a low near-term exploitation probability. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog, and no threat actor attribution has been reported (Feedly, Github Advisory).

Exploitation steps

  1. Authentication: Obtain admin-level credentials for the target anything-llm instance (version ≤ 1.9.1), as the vulnerable endpoints require high privileges.
  2. Identify target files: Enumerate the server's directory structure to identify valuable .json files outside the AgentFlows.flowsDir, such as configuration files containing API keys or package.json.
  3. Craft traversal payload: Construct a malicious UUID parameter containing path traversal sequences (e.g., ../../config/settings) that, when processed by path.join and normalizePath, resolves to a path outside the intended flows directory.
  4. Invoke loadFlow: Send an authenticated API request to the loadFlow endpoint with the crafted UUID to read the contents of the targeted .json file, disclosing sensitive configuration data.
  5. Invoke deleteFlow: Alternatively, send an authenticated API request to the deleteFlow endpoint with the traversal payload to delete a critical .json file (e.g., package.json), causing a denial of service (Github Advisory, Patch Commit).

Indicators of compromise

  • Network: Authenticated API requests to AgentFlows endpoints (e.g., /api/agent-flows/load or /api/agent-flows/delete) containing UUID parameters with path traversal sequences such as ../, ..\, or encoded variants (%2e%2e%2f).
  • Logs: Server-side access logs showing requests to AgentFlows endpoints with anomalous UUID values that do not match standard UUID format (e.g., containing directory separators or dots); repeated requests to the same endpoint with varying traversal depths.
  • File System: Unexpected access or modification timestamps on .json files outside the AgentFlows.flowsDir directory; missing or deleted package.json or other critical configuration files.
  • Process: Unexpected application errors or crashes following deletion of critical .json files, potentially indicating a denial-of-service attempt (Github Advisory, Patch Commit).

Mitigation and workarounds

The primary remediation is to upgrade anything-llm to version 1.12.1 or later, which introduces isWithin() boundary checks in the loadFlow, saveFlow, and deleteFlow methods to prevent directory traversal (Patch Commit). As a temporary workaround, restrict admin access to trusted users only and apply network-level controls to limit access to the anything-llm server. Additionally, implement strict input validation on UUID parameters and ensure the application runs with the least-privilege file system permissions to limit the impact of any traversal attempt (Github Advisory).

Community reactions

The vulnerability was reported through the Huntr bug bounty platform and disclosed publicly on April 7, 2026. A brief mention appeared on Bluesky via the CVE tracking account, and several vulnerability aggregation sites (VulDB, cvefeed.io, thehackerwire.com) picked up the disclosure shortly after publication. No significant vendor statements beyond the patch commit or notable researcher commentary beyond the Huntr bounty report have been identified (Huntr Bounty, Github Advisory).

Additional resources


Source: This report was generated using AI

Related Homebrew vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-103678HIGH8.1
  • NixOS logoNixOS
  • tnef
NoNoOct 01, 2026
CVE-2026-103680MEDIUM6.5
  • NixOS logoNixOS
  • tnef
NoNoOct 01, 2026
CVE-2026-103679MEDIUM6.5
  • NixOS logoNixOS
  • tnef
NoNoOct 01, 2026
CVE-2026-100266MEDIUM6.5
  • NixOS logoNixOS
  • hub
NoYesSep 30, 2026
CVE-2026-100265MEDIUM6.5
  • NixOS logoNixOS
  • rider
NoYesSep 30, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management