{"id":"CVE-2026-41318","summary":"AnythingLLM vulnerable to stored DOM XSS in chart caption renderer - LLM-driven prompt injection produces executable HTML via unsanitized renderMarkdown(content.caption) in Chartable component","details":"AnythingLLM is an application that turns pieces of content into context that any LLM can use as references during chatting. Prior to version 1.12.1, AnythingLLM's in-chat markdown renderer has an unsafe custom rule for images that interpolates the markdown image's `alt` text into an HTML `alt=\"...\"` attribute without any HTML encoding. Every call-site in the app wraps `renderMarkdown(...)` with `DOMPurify.sanitize(...)` as defense-in-depth — except the `Chartable` component, which renders chart captions with no sanitization. The chart caption is the natural-language text the LLM emits around a `create-chart` tool call, so any attacker who can influence the LLM's output — most cheaply via indirect prompt injection in a shared workspace document, or directly if they can create a chart record in a multi-user workspace — can trigger stored DOM-level XSS in every other user's browser when they open that conversation. AnythingLLM chat history is loaded server-side via `GET /api/workspace/:slug/chats` and rendered directly into the chat UI. Version 1.12.1 contains a patch for this issue.","aliases":["GHSA-4q6m-qh3w-9gf5"],"modified":"2026-08-07T11:50:18.345636380Z","published":"2026-04-24T02:57:16.193Z","database_specific":{"cna_assigner":"GitHub_M","cwe_ids":["CWE-116","CWE-1336","CWE-79"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/41xxx/CVE-2026-41318.json"},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/41xxx/CVE-2026-41318.json"},{"type":"ADVISORY","url":"https://github.com/Mintplex-Labs/anything-llm/security/advisories/GHSA-4q6m-qh3w-9gf5"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-41318"},{"type":"FIX","url":"https://github.com/Mintplex-Labs/anything-llm/commit/f5fa03f4728e483949f6360093bc3ea1ef555535"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/mintplex-labs/anything-llm","events":[{"introduced":"0"},{"fixed":"f144692903305b0dfa24efe30e5192b3eea81fed"},{"fixed":"f5fa03f4728e483949f6360093bc3ea1ef555535"}],"database_specific":{"extracted_events":[{"introduced":"0"},{"fixed":"1.12.1"}],"source":["CPE_RANGE","REFERENCES"],"cpe":"cpe:2.3:a:mintplexlabs:anythingllm:*:*:*:*:*:*:*:*"}}],"versions":["v1.12.0","v1.11.2","v1.11.1","v1.11.0","v1.10.0","v1.9.1","v1.9.0","v1.8.5","v1.8.4","v1.8.3","v1.8.2","v1.8.1","v1.8.0","v1.7.8","v1.7.6","v1.7.5","v1.7.4","v1.4.0","v1.3.0","v1.2.3","v1.2.2","v1.2.1","v1.2.0","v1.1.1","v1.1.0","v1.0.0"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-41318.json"}}],"schema_version":"1.8.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:H/I:L/A:N"}]}