HIGH
CVE-2026-90603
CVSS
7.3
Description
A vulnerability was identified in Anil-matcha Open-Generative-AI up to 1.0.11/2.0.0. Affected by this issue is some unknown functionality of the file /api/upload-binary of the component S3 Upload. Such manipulation of the argument x-proxy-target-url leads to unrestricted upload. The attack may be launched remotely. The name of the patch is f013270957f75e439eaf97eb2a93decb32a4543e. Applying a patch is advised to resolve this issue.
Weakness (CWE)
CWE-284
Improper Access Control
CWE-434
Unrestricted File Upload
EPSS Score
0.48%
Probability of exploitation in next 30 days
40.4th percentile
References
https://github.com/Anil-matcha/Open-Generative-AI/
https://github.com/Anil-matcha/Open-Generative-AI/commit/f013270957f75e439eaf97eb2a93decb32a4543e
https://github.com/Anil-matcha/Open-Generative-AI/issues/310
https://vuldb.com/cve/CVE-2026-90603
https://vuldb.com/submit/914005
https://vuldb.com/vuln/403185
https://vuldb.com/vuln/403185/cti
Base CVE data derived from NVD (public domain). Enrichment by
dbcve.org
(CC-BY-4.0). Fetched via API.