CVE-2026-90602 | Anil-matcha Open-Generative-AI up to 1.0.11/2.0.0 Studio Components ImageStudio.js renderHistory cross site scripting (Issue 309)

SecurityVulns

A vulnerability marked as problematic has been reported in Anil-matcha Open-Generative-AI up to 1.0.11/2.0.0. Affected by this vulnerability is the function renderHistory of the file ImageStudio.js of the component Studio Components. This manipulation causes cross site scripting.

This vulnerability appears as CVE-2026-90602. The attack may be initiated remotely. There is no available exploit.

The pull request to fix this issue awaits acceptance.VulDB Recent EntriesRead More