# CVE-2026-90603

## Summary

- **CVE ID:** CVE-2026-90603
- **Severity:** MEDIUM
- **CVSS Score:** 7.5 (CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X)
- **CWE:** CWE-434, CWE-284
- **Published:** Sep 13, 2026
- **Last Modified:** Sep 16, 2026

## Description

A vulnerability was identified in Anil-matcha Open-Generative-AI up to 1.0.11/2.0.0. Affected by this issue is some unknown functionality of the file /api/upload-binary of the component S3 Upload. Such manipulation of the argument x-proxy-target-url leads to unrestricted upload. The attack may be launched remotely. The name of the patch is f013270957f75e439eaf97eb2a93decb32a4543e. Applying a patch is advised to resolve this issue.

## Affected Products

- Anil-matcha — Open-Generative-AI (1.0.0)
- Anil-matcha — Open-Generative-AI (1.0.1)
- Anil-matcha — Open-Generative-AI (1.0.2)
- Anil-matcha — Open-Generative-AI (1.0.3)
- Anil-matcha — Open-Generative-AI (1.0.4)
- Anil-matcha — Open-Generative-AI (1.0.5)
- Anil-matcha — Open-Generative-AI (1.0.6)
- Anil-matcha — Open-Generative-AI (1.0.7)
- Anil-matcha — Open-Generative-AI (1.0.8)
- Anil-matcha — Open-Generative-AI (1.0.9)
- Anil-matcha — Open-Generative-AI (1.0.10)
- Anil-matcha — Open-Generative-AI (1.0.11)
- Anil-matcha — Open-Generative-AI (2.0)

## References

- [CNA](https://vuldb.com/vuln/403185)
- [CNA](https://vuldb.com/vuln/403185/cti)
- [CNA](https://vuldb.com/cve/CVE-2026-90603)
- [CNA](https://vuldb.com/submit/914005)
- [CNA](https://github.com/Anil-matcha/Open-Generative-AI/issues/310)
- [CNA](https://github.com/Anil-matcha/Open-Generative-AI/commit/f013270957f75e439eaf97eb2a93decb32a4543e)
- [CNA](https://github.com/Anil-matcha/Open-Generative-AI/)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 0.48%
- **EPSS Percentile:** 40.2

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-17._