Impact
A flaw in the /api/upload-binary endpoint of Anil‑matcha Open‑Generative‑AI allows an attacker to manipulate the x‑proxy‑target‑url header, causing the component to store an arbitrary file in the configured S3 bucket. The change creates any file type that can be uploaded, potentially breaching data confidentiality and integrity. The description states the attack may be launched remotely; it does not specify an authentication requirement or whether the uploaded content can be executed, so the precise impact on execution is uncertain.
Affected Systems
Versions of Anil‑matcha Open‑Generative‑AI up to and including 1.0.11 and 2.0.0 are affected. Any deployment that exposes the default /api/upload-binary endpoint without restrictions is therefore vulnerable.
Risk and Exploitability
The CVSS score of 6.9 indicates moderate severity, while the EPSS score of less than 1% suggests a low probability of exploitation. The vulnerability is not listed in the CISA KEV catalog. Based on the description, the likely attack vector is remote, requiring only crafted HTTP requests that alter the x‑proxy‑target‑url header. The potential consequences include unchecked storage of arbitrary files in an S3 bucket, which could lead to data exposure or manipulation of downstream processing.
OpenCVE Enrichment