Skip to content

Hide Navigation Hide TOC

AnythingLLM collector /process filename Path Traversal Arbitrary File Deletion (CVE-2023-5832) - ATR-2026-01978 (a1754f02-a245-5402-b6ff-68e1d624d417)

CVE-2023-5832: mintplex-labs/anything-llm < 0.1.0 collector API exposes POST /process which passes the request JSON 'filename' field straight into process_single(WATCH_DIRECTORY, filename) without normalization. A filename containing ../ directory-traversal sequences escapes the hotdir / WATCH_DIRECTORY and lets a low-privilege user delete arbitrary files (e.g. ../../server/storage/anythingllm.db). This rule keys on the /process + filename + ../ traversal triad and on traversal payloads targeting anythingllm storage from the collector context.

Cluster A Galaxy A Cluster B Galaxy B Level
Exploit Public-Facing Application (47d73872-5336-44f7-81e3-d30bc7e039dd) MITRE ATLAS Attack Pattern AnythingLLM collector /process filename Path Traversal Arbitrary File Deletion (CVE-2023-5832) - ATR-2026-01978 (a1754f02-a245-5402-b6ff-68e1d624d417) Agent Threat Rules 1
AnythingLLM collector /process filename Path Traversal Arbitrary File Deletion (CVE-2023-5832) - ATR-2026-01978 (a1754f02-a245-5402-b6ff-68e1d624d417) Agent Threat Rules Exploit Public-Facing Application - T1190 (3f886f2a-874f-4333-b794-aa6075009b1c) Attack Pattern 1