CyberRota Analysis
AI-GeneratedAnil-matcha Open-Generative-AI versions up to 1.0.11 and 2.0.0 are vulnerable due to unrestricted file upload capabilities in the S3 Upload component, specifically through the /api/upload-binary endpoint. This flaw allows remote attackers to exploit the x-proxy-target-url argument, potentially leading to unauthorized file uploads and system compromise. Organizations using affected versions should prioritize applying the patch f013270957f75e439eaf97eb2a93decb32a4543e to mitigate this high-severity risk.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
A vulnerability was identified in Anil-matcha Open-Generative-AI up to 1.0.11/2.0.0. Affected by this issue is some unknown functionality of the file /api/upload-binary of the component S3 Upload. Such manipulation of the argument x-proxy-target-url leads to unrestricted upload. The attack may be launched remotely. The name of the patch is f013270957f75e439eaf97eb2a93decb32a4543e. Applying a patch is advised to resolve this issue.