CVE-2026-90602: Cross Site Scripting in Anil-matcha Open-Generative-AI
A vulnerability was determined in Anil-matcha Open-Generative-AI up to 1.0.11/2.0.0. Affected by this vulnerability is the function renderHistory of the file ImageStudio.js of the component Studio Components. This manipulation causes cross site scripting. The attack may be initiated remotely. The pull request to fix this issue awaits acceptance.
AI Analysis
Technical Summary
Anil-matcha Open-Generative-AI versions 1.0.0 to 1.0.11 and 2.0.0 contain a cross-site scripting vulnerability in the renderHistory function of ImageStudio.js in the Studio Components. This vulnerability allows remote attackers to inject malicious scripts, potentially leading to client-side code execution. The vulnerability is confirmed but the pull request for the fix is pending acceptance, so no official patch is currently available.
Potential Impact
The vulnerability enables remote attackers to perform cross-site scripting attacks, which can lead to the execution of arbitrary scripts in the context of the affected application. This may result in session hijacking, defacement, or other client-side impacts. The CVSS score of 5.1 indicates a medium severity level with network attack vector and low privileges required.
Mitigation Recommendations
No official patch is currently available as the fix is pending acceptance in a pull request. Users should monitor the vendor's repository or advisory channels for the acceptance and release of the fix. Until then, consider applying manual code review or temporary input sanitization in the renderHistory function to mitigate the risk.
CVE-2026-90602: Cross Site Scripting in Anil-matcha Open-Generative-AI
Description
A vulnerability was determined in Anil-matcha Open-Generative-AI up to 1.0.11/2.0.0. Affected by this vulnerability is the function renderHistory of the file ImageStudio.js of the component Studio Components. This manipulation causes cross site scripting. The attack may be initiated remotely. The pull request to fix this issue awaits acceptance.
CVSS v4.0
Score 5.1medium
Affected software
Anil-matcha
Open-Generative-AI
pkg:github/anil-matcha/Open-Generative-AIcpe:2.3:a:anil-matcha:open-generative-ai:*:*:*:*:*:*:*:*Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
Anil-matcha Open-Generative-AI versions 1.0.0 to 1.0.11 and 2.0.0 contain a cross-site scripting vulnerability in the renderHistory function of ImageStudio.js in the Studio Components. This vulnerability allows remote attackers to inject malicious scripts, potentially leading to client-side code execution. The vulnerability is confirmed but the pull request for the fix is pending acceptance, so no official patch is currently available.
Potential Impact
The vulnerability enables remote attackers to perform cross-site scripting attacks, which can lead to the execution of arbitrary scripts in the context of the affected application. This may result in session hijacking, defacement, or other client-side impacts. The CVSS score of 5.1 indicates a medium severity level with network attack vector and low privileges required.
Mitigation Recommendations
No official patch is currently available as the fix is pending acceptance in a pull request. Users should monitor the vendor's repository or advisory channels for the acceptance and release of the fix. Until then, consider applying manual code review or temporary input sanitization in the renderHistory function to mitigate the risk.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- VulDB
- Date Reserved
- 2026-09-12T19:22:09.616Z
- Cvss Version
- 4.0
- State
- PUBLISHED
Threat ID: 6aa72b6955bf5e2cf52e37fa
Added to database: 09/13/2026, 23:02:01 UTC
Last enriched: 09/13/2026, 23:16:35 UTC
Last updated: 09/14/2026, 04:01:22 UTC
Views: 8
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.