HIGH

CVE-2026-90603

2026-09-13 CVSS v3.1
CVSS
7.3

Description

A vulnerability was identified in Anil-matcha Open-Generative-AI up to 1.0.11/2.0.0. Affected by this issue is some unknown functionality of the file /api/upload-binary of the component S3 Upload. Such manipulation of the argument x-proxy-target-url leads to unrestricted upload. The attack may be launched remotely. The name of the patch is f013270957f75e439eaf97eb2a93decb32a4543e. Applying a patch is advised to resolve this issue.

Weakness (CWE)

CWE-284 Improper Access Control
CWE-434 Unrestricted File Upload

EPSS Score

0.48%
Probability of exploitation in next 30 days
40.4th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE