CVE-2026-90603 Details
Description
A vulnerability was identified in Anil-matcha Open-Generative-AI up to 1.0.11/2.0.0. Affected by this issue is some unknown functionality of the file /api/upload-binary of the component S3 Upload. Such manipulation of the argument x-proxy-target-url leads to unrestricted upload. The attack may be launched remotely. The name of the patch is f013270957f75e439eaf97eb2a93decb32a4543e. Applying a patch is advised to resolve this issue.
A vulnerability in Anil-matcha Open-Generative-AI versions through 1.0.11/2.0.0 allows for unrestricted file uploads to an S3 backend. This issue arises from the '/api/upload-binary' and '/api/v1/upload-binary' endpoints, which accept multipart form data including a client-controlled 'x-proxy-target-url' S3 destination. The vulnerability is exacerbated by unauthenticated endpoints that provide presigned S3 upload credentials. As a result, an attacker can upload malicious files, such as executables or HTML/SVG files, which could be used for phishing or to distribute malware.
Users are advised to update to version 1.0.12 or 2.0.1, where this vulnerability has been patched.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Sep 13, 2026CISA-ADP
Assessed Sep 16, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/Anil-matcha/Open-Generative-AI/ | [email protected] | Vendor |
| https://github.com/Anil-matcha/Open-Generative-AI/commit/f013270957f75e439eaf97eb2a93decb32a4543e | [email protected] | Source CodeVendor |
| https://github.com/Anil-matcha/Open-Generative-AI/issues/310 | [email protected] | ExploitIssue TrackingTechnical DescriptionVendor |
| https://vuldb.com/cve/CVE-2026-90603 | [email protected] | AdvisoryPermission Required |
| https://vuldb.com/submit/914005 | [email protected] | Issue TrackingPermission Required |
| https://vuldb.com/vuln/403185 | [email protected] | AdvisoryPermission Required |
| https://vuldb.com/vuln/403185/cti | [email protected] | Content Wall |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-284 | Improper Access Control | [email protected] |
| CWE-434 | Unrestricted Upload of File with Dangerous Type | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| Anil-matcha Open-Generative-AI | <= 1.0.11 (semver) <= 2.0.0 (semver) |
CPE
Remediation
| |
Change History
2 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Sep 16, 2026 | CVE Modified | CISA-ADP |
| Sep 13, 2026 | New CVE Received | [email protected] |
Volerion