Junglewise Threat Intelligence

CVE-2026-90602: Anil-matcha Open-Generative-AI cross-site scripting in Studio history rendering

CVE-2026-90602 · Severity: low · CVSS 3.5 · Published 2026-09-13

Executive brief

Open-Generative-AI is an open-source AI image and video generation studio. The application contains a cross-site scripting (XSS) vulnerability in its studio history feature, where unsanitized data from browser storage is inserted directly into the page when the application loads. An attacker can inject malicious scripts that execute in the context of the user's session, potentially compromising sensitive data or performing unauthorized actions.

Technical details

This is a DOM-based cross-site scripting (XSS) vulnerability in the renderHistory function of ImageStudio.js and related studio components. The vulnerability stems from unsanitized localStorage data being directly injected into innerHTML without proper sanitization. The attack is triggered automatically on page load when users access the application, requiring no special user interaction beyond opening the app. An attacker who can control localStorage data (through a prior compromise or persistent XSS) can achieve arbitrary JavaScript execution. A pull request to fix this issue has been submitted but is awaiting acceptance.

Affected products

  • Anil-matcha Open-Generative-AI up to 1.0.11 and 2.0.0

Timeline

  • 2026-09-13: disclosed: Vulnerability publicly disclosed via CVE-2026-90602

References

Related threats