CVE-2026-90603

A vulnerability was identified in Anil-matcha Open-Generative-AI up to 1.0.11/2.0.0. Affected by this issue is some unknown functionality of the file /api/upload-binary of the component S3 Upload. Such manipulation of the argument x-proxy-target-url leads to unrestricted upload. The attack may be launched remotely. The name of the patch is f013270957f75e439eaf97eb2a93decb32a4543e. Applying a patch is advised to resolve this issue.
Configurations

No configuration.

History

No history.

Information

Published : 2026-09-13 23:16

Updated : 2026-09-14 20:56


NVD link : CVE-2026-90603

Mitre link : CVE-2026-90603

CVE.ORG link : CVE-2026-90603


JSON object : View

Products Affected

No product.

CWE
CWE-284

Improper Access Control

CWE-434

Unrestricted Upload of File with Dangerous Type