Impact
Cheshire Cat AI core through 2.0.23 contains a stored cross‑site scripting vulnerability in its uploads plugin. Authenticated users can upload arbitrary HTML files without MIME or extension restrictions via POST /uploads. When a victim accesses the public GET /uploads/{path} URL, malicious script runs in the application origin, leveraging the victim's access_token cookie—including administrative sessions. The attack allows a malicious user to execute arbitrary client‑side code with the victim's privileges, compromising confidentiality, integrity, and potentially enabling further exploitation.
Affected Systems
Vendor: Cheshire Cat AI, Product: core, affected version up to 2.0.23. No updated versions are specified in the provided data.
Risk and Exploitability
The CVSS score of 5.1 indicates medium severity. EPSS data is not available and the vulnerability is not listed in CISA KEV. Exploitation requires an attacker to first gain authenticated access to upload an HTML file, then to cause a target to load the resulting URL. Because the script executes with the victim's access_token, the impact can be severe if the victim is an administrator. The lack of file type restrictions makes the upload step straightforward, but the social‑engineering step to get the victim to visit the malicious URL limits immediate widespread impact. The overall risk is moderate, with potential for elevated impact if attackers can successfully target privileged accounts.
OpenCVE Enrichment