SEPTEMBER 15, 2026
Live Feed
Back to database
Case File

CVE-2026-90603

HIGH · CVSS 7.3 EPSS 0.48% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-09-13 · Last synced 2026-09-15

CyberRota Analysis

AI-Generated

Anil-matcha Open-Generative-AI versions up to 1.0.11 and 2.0.0 are vulnerable due to unrestricted file upload capabilities in the S3 Upload component, specifically through the /api/upload-binary endpoint. This flaw allows remote attackers to exploit the x-proxy-target-url argument, potentially leading to unauthorized file uploads and system compromise. Organizations using affected versions should prioritize applying the patch f013270957f75e439eaf97eb2a93decb32a4543e to mitigate this high-severity risk.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-90603
Severity
HIGH
CVSS
7.3
EPSS
0.48%

Original NVD Description

A vulnerability was identified in Anil-matcha Open-Generative-AI up to 1.0.11/2.0.0. Affected by this issue is some unknown functionality of the file /api/upload-binary of the component S3 Upload. Such manipulation of the argument x-proxy-target-url leads to unrestricted upload. The attack may be launched remotely. The name of the patch is f013270957f75e439eaf97eb2a93decb32a4543e. Applying a patch is advised to resolve this issue.