CVE-2026-41318: Stored XSS in AnythingLLM via Unsanitized Chart Captions
A stored XSS vulnerability in AnythingLLM's Chartable Markdown renderer lets attacker-controlled chart captions execute arbitrary JavaScript in another user's browser — with a full proof-of-concept walkthrough.