Retour à la veille

CVE-2026-90602

Publié : 13 septembre 2026
Modifié : 13 septembre 2026
Lien officiel NVD
Score CVSS
3.5
LOW

Description détaillée

A vulnerability was determined in Anil-matcha Open-Generative-AI up to 1.0.11/2.0.0. Affected by this vulnerability is the function renderHistory of the file ImageStudio.js of the component Studio Components. This manipulation causes cross site scripting. The attack may be initiated remotely. The pull request to fix this issue awaits acceptance.

Vecteur d'attaque (CVSS)

Vecteur brut :CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N

Références et Patchs