CVE-2026-90602: Anil-Matcha Open-Generative-Ai
Low severity, CVSS 3.5. EPSS: 0.4% chance of exploitation in the next 30 days.
A vulnerability was determined in Anil-matcha Open-Generative-AI up to 1.0.11/2.0.0. Affected by this vulnerability is the function renderHistory of the file ImageStudio.js of the component Studio Components. This manipulation causes cross site scripting. The attack may be initiated remotely. The pull request to fix this issue awaits acceptance.
Affected products
- Anil-Matcha Open-Generative-Ai: version 1.0.0 only; version 1.0.1 only; version 1.0.2 only; version 1.0.3 only; version 1.0.4 only; version 1.0.5 only; …
Published 2026-09-13. Last modified 2026-09-14.