CVE-2026-32719 | Mintplex-Labs anything-llm up to 1.11.1 ZIP File Parser imported.js importCommunityItemFromUrl path traversal
A vulnerability has been found in Mintplex-Labs anything-llm up to 1.11.1 and classified as critical. Affected is the function importCommunityItemFromUrl of the file server/utils/agents/imported.js of the component ZIP File Parser. The manipulation leads to path traversal.
This vulnerability is listed as CVE-2026-32719. The attack may be initiated remotely. There is no available exploit.