Press release
Dangerous AI Security Vulnerability Discovered in AnythingLLM – still unpatched.

Malicious code embeds itself and manipulates all chats in the same workspace unnoticed. (© mgm security partners GmbH)
The vulnerability, tracked as CVE-2025-44822, was discovered on March 3, 2025 by mgm security partners and immediately reported to Mintplex Labs. mgm security partners demonstrated how an attacker can exploit the weakness to inject malicious code via a single chat interaction, then target all active or subsequently opened chat histories within the same workspace. Users need only attach one specially crafted document. The manipulations are invisible to the naked eye and can only be revealed through targeted investigation.
The attack begins with the injection of malicious instructions (XPIA) into data sources, which are then processed by the LLM application. This flaw bypasses the built-in security mechanisms of the LLM — from input validation to handling external content. After a successful XPIA attack, an adversary can abuse the markdown formatting functions intended for text styling to exfiltrate sensitive user data to external servers.
Key aspects of the vulnerability:
* Persistent threat: Attackers gain continuous access to all messages of all chats within the same workspace through XPIA in documents.
* Invisible attacks: The malicious instructions can be embedded in documents in a way that makes it nearly impossible for the user to detect the attack.
* Multiple points of attack: Other possible attack vectors exist via plugin integrations, custom agents and tools.
Need for action for affected companies
As Mintplex Labs has not responded even after a 90-day deadline for responsible disclosure of the vulnerability (Responsible Disclosure Procedure) was set and a final request to respond expired, mgm security partners is now publishing the vulnerability found. The current version 1.8.4 as of 29.07.25 is still vulnerable.
There is an increased risk for companies and their employees who use AnythingLLM together with untrusted documents. The outflow of sensitive data is difficult to detect at network level unless HTTP traffic is comprehensively monitored. Therefore, manually checking all chats and documents is currently the only reliable way to detect an attack. Temporary protection measures such as Guardrails can provide support, but do not offer complete security. Until an update for AnythingLLM is released that prevents the automatic integration of external content, no untrusted sources - such as documents, plugins or tools - should be used.
Further information
A detailed description of the vulnerability and the attack process can be found at this link: https://www.mgm-sp.com/anythingllm.
mgm security partners gmbh
Taunusstr. 23
80807 München
Germany
https://www.mgm-sp.com
Herr Thomas Schreiber
089/358680-880
thomas.schreiber@mgm-sp.com
mgm security partners specializes in application security. The company helps customers to develop and deploy software securely - from classic web applications to AI-based systems. This includes sound advice on securing web and mobile applications, implementing DevSecOps strategies and the secure use of generative AI and large language models (LLMs). With penetration tests, code reviews and security analyses as well as tool-supported Application Security Posture Management (ASPM), mgm security partners supports continuous risk monitoring.
This release was published on openPR.
Permanent link to this press release:
Copy
Please set a link in the press area of your homepage to this press release on openPR. openPR disclaims liability for any content contained in this release.
You can edit or delete your press release Dangerous AI Security Vulnerability Discovered in AnythingLLM – still unpatched. here
News-ID: 4127898 • Views: …
More Releases for LLM
Introducing Model Catalog: One Place to Govern Every LLM an Organization Uses
Image: https://www.globalnewslines.com/uploads/2025/07/0c9f6d1adc3c6edfa8146784f3de5a8a.jpg
Platform teams are facing model sprawl: dozens of teams experimenting with LLMs, hundreds of models in use, and no clean way to manage cost, access, or risk.
That's why we're launching Model Catalog - a single control layer to manage access to 1,600+ LLMs across your org. Finally, platform teams get the visibility, governance, and control they've been asking for.
Built for scale and control, Model Catalog enables teams to experiment,…
Emerging Trends Influencing The Growth Of The Large Language Model (LLM) Market: …
The Large Language Model (LLM) Market Report by The Business Research Company delivers a detailed market assessment, covering size projections from 2025 to 2034. This report explores crucial market trends, major drivers and market segmentation by [key segment categories].
How Big Is the Large Language Model (LLM) Market Size Expected to Be by 2034?
The large language model (LLM) market has experienced exponential growth in recent years. It is projected to grow…
Large Language Model(LLM) Market Strategic Trends for 2032
The Large Language Model (LLM) market has emerged as a transformative force in the realm of artificial intelligence, reshaping industries and enhancing human-computer interaction. As the demand for sophisticated natural language processing capabilities surges, LLMs have become integral to applications ranging from chatbots and virtual assistants to automated content generation and data analysis. Their relevance spans across sectors, including healthcare, finance, education, and beyond, reflecting the vast scope and potential…
Top Factor Driving Large Language Model (LLM) Market Growth in 2025: The Role Of …
"How Big Is the Large Language Model (LLM) Market Expected to Be, and What Will Its Growth Rate Be?
The substantial language model (LLM) market sector has seen explosive growth in recent past. Projections show an increase from $3.92 billion in 2024 to $5.03 billion in 2025 with a composite annual growth rate (CAGR) of 28.3%. The previous growth period experienced enhancement due to the broadening of natural language processing (NLP)…
Jenti's Specialized LLM: Building a Safer, Smarter AI Model Beyond GPT-4
2024 marked the year of increased interest in generative AI technology, a chat-bot service based on RAG(Retrieval-Augmented Generation. These services give out answers similar to a new company recruit. They make mistakes, they do write up reports but they've got a long way to go. But with the proper directions, they understand and apply it well.
In August 2024, Jenti Inc. along with Hyundai Engineering developed the first plant specialized large…
Global Large Language Model(LLM) Market Research Report 2023
Global Large Language Model (LLM) Market
The global Large Language Model(LLM) market was valued at US million in 2022 and is anticipated to reach US million by 2029, witnessing a CAGR of % during the forecast period 2023-2029. The influence of COVID-19 and the Russia-Ukraine War were considered while estimating market sizes.
A big language model is one that has a large capacity for deep learning tasks and typically has a complicated…