A vulnerability was determined in Anil-matcha Open-Generative-AI up to 1.0.11/2.0.0. (CVE-2026-90602)
A cross-site scripting (XSS) vulnerability exists in the renderHistory function of the ImageStudio.js file within the Studio Components of Anil-matcha Open-Generative-AI versions up to 1.0.11 and 2.0.0. This vulnerability can be triggered remotely and allows limited integrity impact without confidentiality or availability loss. A fix has been proposed but is pending acceptance.
AI Analysis
Technical Summary
CVE-2026-90602 identifies a cross-site scripting vulnerability in the renderHistory function of the ImageStudio.js component in Anil-matcha Open-Generative-AI up to versions 1.0.11 and 2.0.0. The vulnerability allows remote attackers to perform script injection, potentially impacting data integrity. The vulnerability has a CVSS 3.1 base score of 3.5, indicating low to medium severity. A pull request containing a fix is available but has not yet been merged or officially released.
Potential Impact
The vulnerability allows remote attackers to inject scripts via the renderHistory function, causing cross-site scripting. The impact is limited to integrity loss, with no confidentiality or availability impact reported. The CVSS score of 3.5 reflects a low to medium severity risk.
Mitigation Recommendations
A fix for this vulnerability is not yet officially released; a pull request addressing the issue is awaiting acceptance. Until the fix is merged and released, users should exercise caution when handling untrusted input in the affected function. Monitor the project's repository for the acceptance of the pull request and apply the official patch once available.
A vulnerability was determined in Anil-matcha Open-Generative-AI up to 1.0.11/2.0.0. (CVE-2026-90602)
Description
A cross-site scripting (XSS) vulnerability exists in the renderHistory function of the ImageStudio.js file within the Studio Components of Anil-matcha Open-Generative-AI versions up to 1.0.11 and 2.0.0. This vulnerability can be triggered remotely and allows limited integrity impact without confidentiality or availability loss. A fix has been proposed but is pending acceptance.
CVSS v3.1
Score 3.5low
Affected software
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
CVE-2026-90602 identifies a cross-site scripting vulnerability in the renderHistory function of the ImageStudio.js component in Anil-matcha Open-Generative-AI up to versions 1.0.11 and 2.0.0. The vulnerability allows remote attackers to perform script injection, potentially impacting data integrity. The vulnerability has a CVSS 3.1 base score of 3.5, indicating low to medium severity. A pull request containing a fix is available but has not yet been merged or officially released.
Potential Impact
The vulnerability allows remote attackers to inject scripts via the renderHistory function, causing cross-site scripting. The impact is limited to integrity loss, with no confidentiality or availability impact reported. The CVSS score of 3.5 reflects a low to medium severity risk.
Mitigation Recommendations
A fix for this vulnerability is not yet officially released; a pull request addressing the issue is awaiting acceptance. Until the fix is merged and released, users should exercise caution when handling untrusted input in the affected function. Monitor the project's repository for the acceptance of the pull request and apply the official patch once available.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- GHSA-4983-r678-hfh4
- Osv Schema Version
- 1.4.0
- Aliases
- ["CVE-2026-90602"]
- Database Specific Severity
- MODERATE
- Cvss Version
- 3.1
- State
- PUBLISHED
Threat ID: 6aa74f9b55bf5e2cf5591b27
Added to database: 09/14/2026, 01:36:27 UTC
Last enriched: 09/14/2026, 01:47:10 UTC
Last updated: 09/14/2026, 03:01:22 UTC
Views: 4
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.