{"id":"CVE-2026-90603","title":"A vulnerability was identified in Anil-matcha Open-Generative-AI up to 1.0.11/2.0.0","summary":"A vulnerability was identified in Anil-matcha Open-Generative-AI up to 1.0.11/2.0.0. Affected by this issue is some unknown functionality of the file /api/upload-binary of the component S3 Upload. Such manipulation of the argument x-prox…","severity":"high","cvss":7.3,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L","cwe":["CWE-284","CWE-434"],"vendor":"Anil-matcha","product":"Open-Generative-AI","affected":["Open-Generative-AI 1.0.0","Open-Generative-AI 1.0.1","Open-Generative-AI 1.0.2","Open-Generative-AI 1.0.3","Open-Generative-AI 1.0.4","Open-Generative-AI 1.0.5","Open-Generative-AI 1.0.6","Open-Generative-AI 1.0.7","Open-Generative-AI 1.0.8","Open-Generative-AI 1.0.9","Open-Generative-AI 1.0.10","Open-Generative-AI 1.0.11","Open-Generative-AI 2.0"],"published":"2026-09-13","updated":"2026-09-16","sourceUpdated":"2026-09-16T15:18:33.417","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-90603","references":[{"url":"https://github.com/Anil-matcha/Open-Generative-AI/","label":"cna@vuldb.com"},{"url":"https://github.com/Anil-matcha/Open-Generative-AI/commit/f013270957f75e439eaf97eb2a93decb32a4543e","label":"cna@vuldb.com"},{"url":"https://github.com/Anil-matcha/Open-Generative-AI/issues/310","label":"cna@vuldb.com"},{"url":"https://vuldb.com/cve/CVE-2026-90603","label":"cna@vuldb.com"},{"url":"https://vuldb.com/submit/914005","label":"cna@vuldb.com"},{"url":"https://vuldb.com/vuln/403185","label":"cna@vuldb.com"},{"url":"https://vuldb.com/vuln/403185/cti","label":"cna@vuldb.com"}],"tags":["nvd","cve.org"],"epss":0.00478,"epssPercentile":0.40471,"ssvc":{"exploitation":"none","automatable":"yes","technicalImpact":"partial","timestamp":"2026-09-16T14:20:41.383540Z"},"ingestedAt":"2026-09-14T15:23:07.468Z","slug":"CVE-2026-90603","body":"## Overview\n\nA vulnerability was identified in Anil-matcha Open-Generative-AI up to 1.0.11/2.0.0. Affected by this issue is some unknown functionality of the file /api/upload-binary of the component S3 Upload. Such manipulation of the argument x-proxy-target-url leads to unrestricted upload. The attack may be launched remotely. The name of the patch is f013270957f75e439eaf97eb2a93decb32a4543e. Applying a patch is advised to resolve this issue.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"twilight","depthScore":40,"depthScoreParts":{"impact":40.2,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[]}