CVE-2026-90602

A vulnerability was determined in Anil-matcha Open-Generative-AI up to 1.0.11/2.0.0. Affected by this vulnerability is the function renderHistory of the file ImageStudio.js of the component Studio Components. This manipulation causes cross site scripting. The attack may be initiated remotely. The pull request to fix this issue awaits acceptance.
Configurations

No configuration.

History

No history.

Information

Published : 2026-09-13 23:16

Updated : 2026-09-14 20:56


NVD link : CVE-2026-90602

Mitre link : CVE-2026-90602

CVE.ORG link : CVE-2026-90602


JSON object : View

Products Affected

No product.

CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

CWE-94

Improper Control of Generation of Code ('Code Injection')