CVE-2026-90602
Received Received - Intake

Cross-Site Scripting in Anil-matcha Open-Generative-AI

Vulnerability report for CVE-2026-90602, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-13

Last updated on: 2026-09-13

Assigner: VulDB

Description

A vulnerability was determined in Anil-matcha Open-Generative-AI up to 1.0.11/2.0.0. Affected by this vulnerability is the function renderHistory of the file ImageStudio.js of the component Studio Components. This manipulation causes cross site scripting. The attack may be initiated remotely. The pull request to fix this issue awaits acceptance.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-13
Last Modified
2026-09-13
Generated
2026-09-14
AI Q&A
2026-09-14
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
anil-matcha open-generative-ai to 1.0.11 (inc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-79 The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
CWE-94 The product constructs all or part of a code segment using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the syntax or behavior of the intended code segment.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is a cross-site scripting (XSS) issue in Anil-matcha Open-Generative-AI versions up to 1.0.11 and 2.0.0. It exists in the renderHistory function of ImageStudio.js within the Studio Components. An attacker can remotely initiate an XSS attack by manipulating this function.

Impact Analysis

This vulnerability allows attackers to inject malicious scripts into web pages viewed by users. This could lead to theft of session cookies, account takeover, or defacement of web pages. Users with access to the affected component may be exposed to these risks.

Compliance Impact

This XSS vulnerability could lead to unauthorized access to sensitive user data, violating GDPR's data protection principles. For HIPAA, it may compromise protected health information if exploited. Both regulations require protection against such attacks to ensure data confidentiality and integrity.

Mitigation Strategies

Update Anil-matcha Open-Generative-AI to a version beyond 1.0.11 or 2.0.0 where the vulnerability in ImageStudio.js is fixed. Monitor for the pull request acceptance and apply the patch once available.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-90602. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart