Retour à la veille

CVE-2026-108725

Publié : 11 octobre 2026
Modifié : 11 octobre 2026
Lien officiel NVD
Score CVSS
5.4
MEDIUM

Description détaillée

Cheshire Cat AI core through 2.0.23 contains a stored cross-site scripting vulnerability in the uploads plugin that allows authenticated users to upload HTML files via POST /uploads without type restrictions. Attackers can send the public GET /uploads/{path} URL to a signed-in victim, executing script in the application origin with the victim's access_token cookie, including administrators.

Vecteur d'attaque (CVSS)

Vecteur brut :CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N

Références et Patchs