๐Ÿ” CVE Alert

CVE-2026-105798

HIGH 8.7

SimpleChat: Stored XSS via group document filename in inline onclick handler

CVSS Score
8.7
EPSS Score
0.0%
EPSS Percentile
0th

SimpleChat is a secure AI conversation application with personal and group workspaces for document-grounded interactions. Prior to 0.261.029, POST /api/group_documents/upload stores an attacker-controlled group document filename that group_workspaces.html later interpolates into inline Share event handlers. The escapeGroupHtml function leaves apostrophes unchanged, while escapeHtml produces an HTML entity that the browser decodes before JavaScript evaluation, so either path permits the filename to terminate the handler string. An authenticated group Owner, Admin, or DocumentManager can persist script that executes in the SimpleChat origin when another group member clicks Share, allowing access to victim-visible data and actions with the victim session. This issue is fixed in version 0.261.029.

CWE CWE-79
Vendor microsoft
Product simplechat
Ecosystems
Industries
TechnologyEnterprise
Published Oct 6, 2026
Last Updated Oct 6, 2026
Stay Ahead of the Next One

Get instant alerts for microsoft simplechat

Be the first to know when new high vulnerabilities affecting microsoft simplechat are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N
Attack Vector
Network
Attack Complexity
Low
Privileges Required
Low
User Interaction
Required
Scope
Changed
Confidentiality
High
Integrity
High
Availability
None

Affected Versions

microsoft / simplechat
< 0.261.029

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/microsoft/simplechat/security/advisories/GHSA-qwcw-r653-j8c6 github.com: https://github.com/microsoft/simplechat/commit/537a259eb048b8f6d1c94193fa0c9683ab0bace9