CVE-2026-90603: Anil-matcha Open-Generative-AI S3 Upload upload-binary unrestricted upload
A vulnerability was identified in Anil-matcha Open-Generative-AI up to 1.0.11/2.0.0. Affected by this issue is some unknown functionality of the file /api/upload-binary of the component S3 Upload. Such manipulation of the argument x-proxy-target-url leads to unrestricted upload. The attack may be launched remotely. The name of the patch is f013270957f75e439eaf97eb2a93decb32a4543e. Applying a patch is advised to resolve this issue.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Anil-matcha Open-Generative-AI (S3 Upload) /api/upload-binaryto a version that resolves this vulnerability.Fixed in 1.0.11/2.0.0Patch f013270957f75e439eaf97eb2a93decb32a4543e
Event History
Frequently Asked Questions
Which deployments are affected?
Anil-matcha Open-Generative-AI versions up to 1.0.11 and 2.0.0 are identified as affected. The issue involves unknown functionality in the S3 Upload component's /api/upload-binary endpoint.
What does an attacker need to exploit this issue?
The attack can be launched remotely and does not require privileges or user interaction according to the supplied vector. Exploitation involves manipulating the x-proxy-target-url argument to perform an unrestricted upload.
Is patching available?
Yes. The identified patch is f013270957f75e439eaf97eb2a93decb32a4543e, and applying it is advised.