๐Ÿ” CVE Alert

CVE-2026-108725

MEDIUM 5.4

Cheshire Cat AI core through 2.0.23 Stored XSS via uploads plugin

CVSS Score
5.4
EPSS Score
0.0%
EPSS Percentile
0th

Cheshire Cat AI core through 2.0.23 contains a stored cross-site scripting vulnerability in the uploads plugin that allows authenticated users to upload HTML files via POST /uploads without type restrictions. Attackers can send the public GET /uploads/{path} URL to a signed-in victim, executing script in the application origin with the victim's access_token cookie, including administrators.

CWE CWE-79
Vendor cheshire-cat-ai
Product core
Published Oct 11, 2026
Stay Ahead of the Next One

Get instant alerts for cheshire-cat-ai core

Be the first to know when new medium vulnerabilities affecting cheshire-cat-ai core are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Attack Vector
Network
Attack Complexity
Low
Privileges Required
Low
User Interaction
Required
Scope
Changed
Confidentiality
Low
Integrity
Low
Availability
None

Affected Versions

cheshire-cat-ai / core
0 โ‰ค 2.0.23

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
hackmd.io: https://hackmd.io/@haind03/cheshire-cat-uploads-stored-html-same-origin-xss github.com: https://github.com/cheshire-cat-ai/core/blob/c22731e7009ac89835b1d7b1cabc5989d998ec3e/src/cat/scaffold/plugins/uploads/endpoints.py#L28-L96 github.com: https://github.com/cheshire-cat-ai/core vulncheck.com: https://www.vulncheck.com/advisories/cheshire-cat-ai-core-through-2.0.23-stored-xss-via-uploads-plugin

Credits

HaiND from the Post and Telecommunication Institute of Technology