VYPR

Open Generative AI

by Anil Matcha

CVEs (2)

  • CVE-2026-90603HigSep 13, 2026
    risk 0.40cvss 7.3epss

    A vulnerability was identified in Anil-matcha Open-Generative-AI up to 1.0.11/2.0.0. Affected by this issue is some unknown functionality of the file /api/upload-binary of the component S3 Upload. Such manipulation of the argument x-proxy-target-url leads to unrestricted upload.…

  • CVE-2026-90602LowSep 13, 2026
    risk 0.16cvss 3.5epss

    A vulnerability was determined in Anil-matcha Open-Generative-AI up to 1.0.11/2.0.0. Affected by this vulnerability is the function renderHistory of the file ImageStudio.js of the component Studio Components. This manipulation causes cross site scripting. The attack may be…