{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/open-generative-ai--1.0.11-2.0.0/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:anil-matcha:open-generative-ai:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":7.3,"id":"CVE-2026-90603"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Open-Generative-AI (\u003c= 1.0.11, 2.0.0)"],"_cs_severities":["high"],"_cs_tags":["vulnerability","remote-code-execution","web-application-security"],"_cs_type":"advisory","_cs_vendors":["Anil-matcha"],"content_html":"\u003cp\u003eA security vulnerability (CVE-2026-90603) has been identified in Anil-matcha Open-Generative-AI versions up to 1.0.11 and 2.0.0. The vulnerability resides in the S3 Upload component within the /api/upload-binary file. An unauthenticated remote attacker can exploit this flaw by manipulating the x-proxy-target-url parameter, which bypasses intended file validation and allows for the upload of arbitrary files to the server. This vulnerability poses a significant risk as it can lead to remote code execution (RCE) if an attacker is able to upload malicious scripts or executables to a web-accessible directory. A patch (f013270957f75e439eaf97eb2a93decb32a4543e) has been released to address this issue.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation of this vulnerability allows remote attackers to upload arbitrary files to the server infrastructure, potentially resulting in full system compromise, data theft, or persistent malware installation. The vulnerability affects all deployments of Open-Generative-AI running versions 1.0.11 or earlier, or the 2.0.0 release.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cp\u003ePrioritize the following actions to secure the environment:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eApply the vendor-provided patch f013270957f75e439eaf97eb2a93decb32a4543e to all instances of Open-Generative-AI immediately.\u003c/li\u003e\n\u003cli\u003eAudit server logs for requests to /api/upload-binary containing unexpected patterns in the x-proxy-target-url parameter.\u003c/li\u003e\n\u003cli\u003eRestrict access to the /api/upload-binary endpoint using network-level controls if immediate patching is not possible.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-09-13T23:27:57Z","date_published":"2026-09-13T23:27:57Z","id":"https://feed.craftedsignal.io/briefs/2026-09-13-cve-2026-90603/","summary":"Anil-matcha Open-Generative-AI is vulnerable to unrestricted file uploads via the /api/upload-binary endpoint, allowing remote attackers to manipulate the x-proxy-target-url argument to upload arbitrary files.","title":"Unrestricted File Upload Vulnerability in Anil-matcha Open-Generative-AI","url":"https://feed.craftedsignal.io/briefs/2026-09-13-cve-2026-90603/"}],"language":"en","title":"CraftedSignal Threat Feed - Open-Generative-AI (\u003c= 1.0.11, 2.0.0)","version":"https://jsonfeed.org/version/1.1"}