{"id":"CVE-2026-90603","summary":"Anil-matcha Open-Generative-AI S3 Upload upload-binary unrestricted upload","details":"A vulnerability was identified in Anil-matcha Open-Generative-AI up to 1.0.11/2.0.0. Affected by this issue is some unknown functionality of the file /api/upload-binary of the component S3 Upload. Such manipulation of the argument x-proxy-target-url leads to unrestricted upload. The attack may be launched remotely. The name of the patch is f013270957f75e439eaf97eb2a93decb32a4543e. Applying a patch is advised to resolve this issue.","modified":"2026-09-15T03:48:22.825272396Z","published":"2026-09-13T23:00:13.818Z","database_specific":{"cwe_ids":["CWE-284","CWE-434"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/90xxx/CVE-2026-90603.json","cna_assigner":"VulDB"},"references":[{"type":"WEB","url":"https://github.com/Anil-matcha/Open-Generative-AI/"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/90xxx/CVE-2026-90603.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-90603"},{"type":"ADVISORY","url":"https://vuldb.com/cve/CVE-2026-90603"},{"type":"ADVISORY","url":"https://vuldb.com/submit/914005"},{"type":"ADVISORY","url":"https://vuldb.com/vuln/403185"},{"type":"REPORT","url":"https://github.com/Anil-matcha/Open-Generative-AI/issues/310"},{"type":"REPORT","url":"https://vuldb.com/vuln/403185/cti"},{"type":"FIX","url":"https://github.com/Anil-matcha/Open-Generative-AI/commit/f013270957f75e439eaf97eb2a93decb32a4543e"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/anil-matcha/open-generative-ai","events":[{"introduced":"38ce0ecbf1b9c906dfd4fc13252ee7f72d46c2c9"},{"fixed":"f013270957f75e439eaf97eb2a93decb32a4543e"}],"database_specific":{"extracted_events":[{"introduced":"1.0.0"},{"last_affected":"1.0.0"},{"introduced":"1.0.1"},{"last_affected":"1.0.1"},{"introduced":"1.0.2"},{"last_affected":"1.0.2"},{"introduced":"1.0.3"},{"last_affected":"1.0.3"},{"introduced":"1.0.4"},{"last_affected":"1.0.4"},{"introduced":"1.0.5"},{"last_affected":"1.0.5"},{"introduced":"1.0.6"},{"last_affected":"1.0.6"},{"introduced":"1.0.7"},{"last_affected":"1.0.7"},{"introduced":"1.0.8"},{"last_affected":"1.0.8"},{"introduced":"1.0.9"},{"last_affected":"1.0.9"},{"introduced":"1.0.10"},{"last_affected":"1.0.10"},{"introduced":"1.0.11"},{"last_affected":"1.0.11"},{"introduced":"2.0"},{"last_affected":"2.0"}],"source":["AFFECTED_FIELD","REFERENCES"]}}],"versions":["1.0.0","1.0.1","1.0.10","1.0.11","1.0.2","1.0.3","1.0.4","1.0.5","1.0.6","1.0.7","1.0.8","1.0.9","2.0","v2.0.0","v1.0.11","v1.0.10","v1.0.9","v1.0.8","v1.0.7","v1.0.6","v1.0.5","v1.0.4","v1.0.3-binaries","v1.0.2","v1.0.1","v1.0.0"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-90603.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X"}]}