Description
A vulnerability was determined in Anil-matcha Open-Generative-AI up to 1.0.11/2.0.0. Affected by this vulnerability is the function renderHistory of the file ImageStudio.js of the component Studio Components. This manipulation causes cross site scripting. The attack may be initiated remotely. The pull request to fix this issue awaits acceptance.
Published: 2026-09-13
Score: 5.1 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Cross-site scripting
Action: Patch
AI Analysis

Impact

This flaw allows an attacker to inject arbitrary script code into the HTML generated by the renderHistory function of the ImageStudio.js component. The impact is that a victim who views a crafted history entry will execute the injected script in their browser. Based on typical XSS behavior, this could lead to session hijacking, page defacement, or redirects, but those outcomes are inferred from general XSS characteristics rather than stated in the description. The vulnerability is categorized as a classic reflected XSS (CWE‑79) that can also be leveraged as a component of a broader code‑execution vector (CWE‑94).

Affected Systems

The affected product is Anil-matcha Open-Generative-AI, specifically versions up to 1.0.11 and 2.0.0. The renderHistory function in Studio Components is the vulnerable code path. The project’s GitHub repository.

Risk and Exploitability

The CVSS score of 5.1 indicates a medium severity. The EPSS score of <1% shows a very low probability of exploitation, and the vulnerability is not listed in CISA KEV. The likely attack vector is remote: an attacker can construct a URL or payload that triggers the renderHistory function when a user navigates to it. If the vulnerable function is exposed in a public or shared environment, the risk to end‑users is elevated, though defenses such as disabling the Studio Components or restricting access mitigate the threat.

Generated by OpenCVE AI on September 15, 2026 at 16:47 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update Open-Generative-AI to a version where the renderHistory exposure is removed or fixed.
  • If an updated release is not yet available, temporarily disable the Studio Components or remove references to renderHistory so the vulnerable code path cannot be reached.
  • Apply strict input validation and escaping on any data that may be passed to renderHistory to ensure no user‑supplied content can be interpreted as script.
  • Implement a strict Content‑Security‑Policy header to block execution of injected scripts in the browser.

Generated by OpenCVE AI on September 15, 2026 at 16:47 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 14 Sep 2026 21:00:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Sun, 13 Sep 2026 23:00:00 +0000

Type Values Removed Values Added
Description A vulnerability was determined in Anil-matcha Open-Generative-AI up to 1.0.11/2.0.0. Affected by this vulnerability is the function renderHistory of the file ImageStudio.js of the component Studio Components. This manipulation causes cross site scripting. The attack may be initiated remotely. The pull request to fix this issue awaits acceptance.
Title Anil-matcha Open-Generative-AI Studio Components ImageStudio.js renderHistory cross site scripting
First Time appeared Anil-matcha
Anil-matcha open-generative-ai
Weaknesses CWE-79
CWE-94
CPEs cpe:2.3:a:anil-matcha:open-generative-ai:*:*:*:*:*:*:*:*
Vendors & Products Anil-matcha
Anil-matcha open-generative-ai
References
Metrics cvssV2_0

{'score': 4, 'vector': 'AV:N/AC:L/Au:S/C:N/I:P/A:N/E:ND/RL:ND/RC:UR'}

cvssV3_0

{'score': 3.5, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N/E:X/RL:X/RC:R'}

cvssV3_1

{'score': 3.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N/E:X/RL:X/RC:R'}

cvssV4_0

{'score': 5.1, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X'}


Subscriptions

Anil-matcha Open-generative-ai
cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-09-14T16:57:04.817Z

Reserved: 2026-09-12T19:22:09.616Z

Link: CVE-2026-90602

cve-icon Vulnrichment

Updated: 2026-09-14T16:56:53.451Z

cve-icon NVD

Status : Deferred

Published: 2026-09-13T23:16:28.520

Modified: 2026-09-14T20:56:48.220

Link: CVE-2026-90602

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-15T17:00:14Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

  • CWE-94

    Improper Control of Generation of Code ('Code Injection')