Medium severity5.4NVD Advisory· Published Oct 11, 2026
CVE-2026-108725
CVE-2026-108725
Description
Cheshire Cat AI core through 2.0.23 contains a stored cross-site scripting vulnerability in the uploads plugin that allows authenticated users to upload HTML files via POST /uploads without type restrictions. Attackers can send the public GET /uploads/{path} URL to a signed-in victim, executing script in the application origin with the victim's access_token cookie, including administrators.
Affected products
1- Range: <=2.0.23
Patches
Vulnerability mechanics
References
3News mentions
0No linked articles in our index yet.