Sceawere

Vulnerability Detail

CVE-2026-105798UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

SimpleChat Stored XSS via Filenames

Vulnerability Metadata

Severity
High
Score / CVSS
8.7
Creation Date
10h ago
Vendor
microsoft
Product
simplechat
Attack Type
CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Vector String
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N
Attack Complexity
LOW

Narrative and Response

Description

SimpleChat is a secure AI conversation application with personal and group workspaces for document-grounded interactions. Prior to 0.261.029, POST /api/group_documents/upload stores an attacker-controlled group document filename that group_workspaces.html later interpolates into inline Share event handlers. The escapeGroupHtml function leaves apostrophes unchanged, while escapeHtml produces an HTML entity that the browser decodes before JavaScript evaluation, so either path permits the filename to terminate the handler string. An authenticated group Owner, Admin, or DocumentManager can persist script that executes in the SimpleChat origin when another group member clicks Share, allowing access to victim-visible data and actions with the victim session. This issue is fixed in version 0.261.029.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "8.7",
  "pubDate": "2026-10-06T15:17:16.880Z",
  "pubdate": "2026-10-06T15:17:16.880Z",
  "executiveSummary": "SimpleChat versions prior to 0.261.029 are susceptible to a Stored Cross-Site Scripting (XSS) vulnerability located within the group document upload functionality.\nThe vulnerability arises from improper neutralization of attacker-controlled input within the group_documents/upload API endpoint, which is subsequently interpolated into inline JavaScript event handlers in group_workspaces.html.\nAn authenticated user with elevated privileges (Owner, Admin, or DocumentManager) can inject malicious scripts into document filenames. This script executes within the context of the victim's session when they interact with the 'Share' feature.\nSuccessful exploitation allows an attacker to compromise the victim's session, gain unauthorized access to sensitive data, and perform actions on behalf of the victim within the SimpleChat origin.\nThe risk is critical due to the persistent nature of the payload and the ability to target other group members, potentially leading to unauthorized data exfiltration or account takeover within the application's trust boundary.",
  "technicalDetails": "The vulnerability resides in the insufficient sanitization of document filenames submitted via the POST /api/group_documents/upload endpoint. The application stores these filenames in its database without applying context-aware encoding, specifically failing to account for the subsequent injection into inline JavaScript event handlers.\nThe client-side component, group_workspaces.html, retrieves these malicious filenames and embeds them directly into inline event handlers associated with the 'Share' functionality. Two specific filtering functions, escapeGroupHtml and escapeHtml, are employed during this process, but both are fundamentally flawed for this context. The escapeGroupHtml function fails to escape apostrophes ('), and the escapeHtml function produces HTML entities that are transparently decoded by the browser before the JavaScript engine processes the containing attribute, thereby enabling string termination.\nAn attacker with Owner, Admin, or DocumentManager privileges can craft a filename containing a payload such as: ';alert(document.cookie);//. Because the handler structure typically resembles onmouseover='share(\"FILENAME\")', the injected apostrophe closes the string, allowing for arbitrary JavaScript injection.\nThe attack flow proceeds as follows: 1) The attacker uploads a document with a maliciously crafted filename containing an XSS payload via the POST /api/group_documents/upload endpoint. 2) The server stores this malicious metadata in the database. 3) A target user visits the group_workspaces.html page and interacts with the 'Share' event handler associated with the attacker's document. 4) The browser executes the injected JavaScript code in the victim's session context. 5) The payload executes within the SimpleChat origin, granting the attacker access to sensitive session data, cookies, or the ability to perform authenticated actions on behalf of the victim.\nThis vulnerability is classified as Stored XSS because the malicious script persists on the server and is served to any user who navigates to the shared document interface. Since the execution occurs within the SimpleChat origin, the Same-Origin Policy (SOP) is bypassed, permitting full access to the victim's interaction with the platform."
}
CVE-2026-105798: SimpleChat Stored XSS via Filenames (HIGH Severity, CVSS: 8.7) | Sceawere