Open-Generative-AI vulnerability

A vulnerability was identified in Anil-matcha Open-Generative-AI up to 1.0.11/2.0.0. Affected by this issue is some unknown functionality of the file /api/upload-binary of the component S3 Upload. Such manipulation of the argument x-proxy-target-url leads to unrestricted upload. The attack may be launched remotely. The name of the patch is f013270957f75e439eaf97eb2a93decb32a4543e. Applying a patch is advised to resolve this issue.

Published 13 Sep 2026Updated 13 Sep 20267 sources
CVSS 6.9

Record history

Record created from the first normalized source observation.
Metadata and source references refreshed.