Sceawere

Vulnerability Detail

CVE-2026-108725UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Cheshire Cat AI Stored XSS

Vulnerability Metadata

Severity
Medium
Score / CVSS
5.4
Creation Date
4h ago
Vendor
cheshire-cat-ai
Product
core
Attack Type
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Vector String
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Attack Complexity
LOW

Narrative and Response

Description

Cheshire Cat AI core through 2.0.23 contains a stored cross-site scripting vulnerability in the uploads plugin that allows authenticated users to upload HTML files via POST /uploads without type restrictions. Attackers can send the public GET /uploads/{path} URL to a signed-in victim, executing script in the application origin with the victim's access_token cookie, including administrators.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "5.4",
  "pubDate": "2026-10-11T13:17:16.137Z",
  "pubdate": "2026-10-11T13:17:16.137Z",
  "executiveSummary": "The Cheshire Cat AI core, up to version 2.0.23, is susceptible to a Stored Cross-Site Scripting (XSS) vulnerability residing within the uploads plugin.\nThe flaw originates from an improper validation mechanism during the file upload process, allowing authenticated users to upload arbitrary HTML files via the POST /uploads endpoint.\nBy bypassing file type restrictions, an attacker can store malicious scripts on the server. When a victim—including users with administrative privileges—accesses the stored file via the public GET /uploads/{path} endpoint, the script executes within the context of the application's origin.\nThis vulnerability poses a critical risk as the execution occurs using the victim's session context, specifically granting the attacker access to the victim's access_token cookie.\nSuccessful exploitation requires the attacker to be an authenticated user of the application and successfully induce a target user to navigate to the malicious URL.\nThe potential impact includes full account takeover, unauthorized actions performed on behalf of the victim, and potential escalation of privileges if an administrator is targeted.",
  "technicalDetails": "The vulnerability is a classic Stored Cross-Site Scripting (XSS) condition facilitated by insufficient input validation within the Cheshire Cat AI uploads plugin.\nThe root cause is the lack of server-side MIME type or file extension verification for the POST /uploads endpoint. The application fails to restrict the ingestion of malicious content, allowing for the persistence of arbitrary HTML documents within the application's storage architecture.\nExploitation follows a multi-stage attack flow. First, an authenticated attacker crafts a malicious HTML file containing JavaScript payloads designed to exfiltrate sensitive data, such as session cookies or access tokens, or to perform unauthorized API requests. This file is submitted to the server via the POST /uploads interface. The application processes the request and saves the file to the public-facing storage directory without sanitization or content-type enforcement.\nSecond, the attacker identifies the public URL path assigned to the uploaded resource, represented by the GET /uploads/{path} endpoint.\nThird, the attacker delivers this URL to a target user—who could be a standard user or an administrator—often through social engineering tactics or direct communication. Upon the victim navigating to the provided URL, the web browser interprets the response as an HTML document due to the lack of restrictive Content-Type headers or proper storage isolation.\nThe malicious script executes within the security context of the Cheshire Cat AI application origin. Because the script runs in the authenticated user's browser, it gains full access to the Document Object Model (DOM) and the application's local storage. Crucially, the script can access the victim's access_token cookie, which is often used for authorization in subsequent API interactions.\nThe scope of impact is significant because the execution occurs with the victim's permissions. If the victim is an administrator, the attacker may gain the ability to manage the platform, modify system configurations, or exfiltrate sensitive data across the entire installation. This vulnerability persists until the malicious file is manually removed from the server, and it remains a constant threat as long as the file is reachable via the public GET endpoint.\nThis issue affects all versions of Cheshire Cat AI core up to and including 2.0.23, necessitating stringent validation controls on all user-submitted content."
}
CVE-2026-108725: Cheshire Cat AI Stored XSS (MEDIUM Severity, CVSS: 5.4) | Sceawere