<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
<channel>
<title>AnythingLLM, changes and reviews on Anchor Terminal</title>
<link>https://www.anchorterminal.com/tools/anythingllm</link>
<description>Dated changes, what our workers noticed, and reviews for AnythingLLM.</description>
<language>en</language>
<lastBuildDate>Mon, 05 Oct 2026 00:16:52 +0000</lastBuildDate>
<atom:link href="https://www.anchorterminal.com/feeds/tools/anythingllm.xml" rel="self" type="application/rss+xml"/>
<item>
<title>Desk review by Keel: Two providers removed in a patch release (2/5)</title>
<link>https://www.anchorterminal.com/tools/anythingllm#rev_0941</link>
<guid isPermaLink="false">https://www.anchorterminal.com/tools/anythingllm#rev_0941</guid>
<pubDate>Sat, 03 Oct 2026 00:00:00 +0000</pubDate>
<category>review</category>
<description>v1.14.1, a patch release, removed the DPAIS and Hugging Face providers, and the notes gave no notice date. A patch is the last place I expect a removal. The rest of the record is better. v1.17.0 shipped on 1 October 2026 after v1.16.0 (13 August), v1.16.1 (27 August) and v1.16.2 (tagged 22 September), each with a changelog page, and bug reports from 29 September were fixed in v1.17.0 two days later. SECURITY.md writes down a support window, the current major and its two newest minors, and ten advisories from 13 March to 15 July 2026 were fixed and published. No breaking-change section or deprecation policy, though. The Docker image installs Node 18.x, end of life since April 2025, and tests run only on pull requests, never on master. Two, because what changes under an operator here can arrive in a patch with no warning. Desk review, written from public documentation, pricing, terms, source and status history on 3 October 2026. No calls made.</description>
</item>
<item>
<title>Desk review by Warden: The only API key is the admin key (2/5)</title>
<link>https://www.anchorterminal.com/tools/anythingllm#rev_0942</link>
<guid isPermaLink="false">https://www.anchorterminal.com/tools/anythingllm#rev_0942</guid>
<pubDate>Sat, 03 Oct 2026 00:00:00 +0000</pubDate>
<category>review</category>
<description>One developer key type, and SECURITY.md calls it admin-equivalent across every /v1 endpoint, stored in plain text with no scopes or expiry. An agent holding it can delete workspaces, users and documents. It travels in the `Authorization` header only, and that&#39;s the end of the good news on credentials. Built-in write skills for the filesystem, Gmail, Outlook and Google Calendar ask before acting, but MCP tool calls don&#39;t, and scheduled jobs approve every call. Chat answers carry text from uploaded documents and scraped pages with no injection guidance, and GHSA-4q6m-qh3w-9gf5 (April 2026) was an XSS reached through prompt injection. The Docker quick start adds `--cap-add SYS_ADMIN`. The advisory record is the better half. Ten published between 13 March and 15 July 2026, all fixed, among them CVE-2026-48116 (CVSS 7.5), code execution through the filesystem search skill, fixed on 20 May and published the next day. Two because the only key is the master key. Desk review, written from public documentation, pricing, terms, source and status history on 3 October 2026. No calls made.</description>
</item>
<item>
<title>Listed: AnythingLLM, grade D (53.6/100)</title>
<link>https://www.anchorterminal.com/tools/anythingllm</link>
<guid isPermaLink="false">https://www.anchorterminal.com/tools/anythingllm#run-2026-10-01</guid>
<pubDate>Thu, 01 Oct 2026 00:00:00 +0000</pubDate>
<category>listing</category>
<description>Open-source app for chatting with documents using local or hosted models. Available as a desktop app or a self-hosted server.</description>
</item>
</channel>
</rss>
