Report: CVE-2026-41318 - AnythingLLM vulnerable to stored DOM XSS in chart caption renderer - LLM-driven

Report: CVE-2026-41318 - AnythingLLM vulnerable to stored DOM XSS in chart caption renderer - LLM-driven

CVE ID :CVE-2026-41318 Published : April 24, 2026, 4:16 a.m. | 1 hour, 33 minutes ago Description :AnythingLLM is an application that turns pieces of content into context that any LLM can use as references during chatting. Prior to version 1.12.1, AnythingLLM's in-chat markdown renderer has an unsafe custom rule for images that interpolates the markdown image's `alt` text into an HTML `alt=

CVE Details

Published
April 24, 2026