Anil Matcha · Open-Generative-Ai · CVE-2026-90602
**Name of the Vulnerable Software and Affected Versions**
Anil-matcha Open-Generative-AI versions 1.0.11 and 2.0.0
**Description**
A remote cross site scripting issue exists within the Studio Components component. The flaw is located in the `renderHistory()` function of the ImageStudio.js file, allowing an attacker to execute malicious scripts remotely.
**Recommendations**
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
As a temporary workaround, consider restricting the use of the `renderHistory()` function in ImageStudio.js to minimize the risk of exploitation.