CVE-2026-105798: SimpleChat: Stored XSS via group document filename in inline onclick handler
SimpleChat is a secure AI conversation application with personal and group workspaces for document-grounded interactions. Prior to 0.261.029, POST /api/groupdocuments/upload stores an attacker-controlled group document filename that groupworkspaces.html later interpolates into inline Share event handlers. The escapeGroupHtml function leaves apostrophes unchanged, while escapeHtml produces an HTML entity that the browser decodes before JavaScript evaluation, so either path permits the filename to terminate the handler string. An authenticated group Owner, Admin, or DocumentManager can persist script that executes in the SimpleChat origin when another group member clicks Share, allowing access to victim-visible data and actions with the victim session. This issue is fixed in version 0.261.029.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
SimpleChatto a version that resolves this vulnerability.Fixed in 0.261.029
Event History
Frequently Asked Questions
Which users can introduce the malicious content, and who is at risk of triggering it?
An authenticated group Owner, Admin, or DocumentManager can upload a group document with a crafted filename. Other members of that group are at risk when they click Share for the affected document.
What interaction is required for exploitation?
The attacker must be authenticated and able to upload group documents in the target group. The stored script executes only when another group member clicks the Share control associated with the crafted filename.
What is the impact if a victim triggers the stored script?
The script runs in the SimpleChat origin with the victim's session, allowing the attacker to access victim-visible data and perform actions available to that victim. Availability impact is not described.
Which versions need remediation?
Versions prior to 0.261.029 are affected. Upgrade to version 0.261.029 to obtain the fix.