CVE-2026-90603 PUBLISHED

Anil-matcha Open-Generative-AI S3 Upload upload-binary unrestricted upload

Assigner: VulDB
Reserved: 12.09.2026 Published: 13.09.2026 Updated: 13.09.2026

A vulnerability was identified in Anil-matcha Open-Generative-AI up to 1.0.11/2.0.0. Affected by this issue is some unknown functionality of the file /api/upload-binary of the component S3 Upload. Such manipulation of the argument x-proxy-target-url leads to unrestricted upload. The attack may be launched remotely. The name of the patch is f013270957f75e439eaf97eb2a93decb32a4543e. Applying a patch is advised to resolve this issue.

Metrics

CVSS Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X
CVSS Score: 6.9

Product Status

Vendor Anil-matcha
Product Open-Generative-AI
Versions
  • Version 1.0.0 is affected
  • Version 1.0.1 is affected
  • Version 1.0.2 is affected
  • Version 1.0.3 is affected
  • Version 1.0.4 is affected
  • Version 1.0.5 is affected
  • Version 1.0.6 is affected
  • Version 1.0.7 is affected
  • Version 1.0.8 is affected
  • Version 1.0.9 is affected
  • Version 1.0.10 is affected
  • Version 1.0.11 is affected
  • Version 2.0 is affected

Credits

  • Practice (VulDB User) reporter

References

Problem Types

  • Unrestricted Upload CWE
  • Improper Access Controls CWE