CVE-2026-108725
Description
Cheshire Cat AI core through 2.0.23 contains a stored cross-site scripting vulnerability in the uploads plugin that allows authenticated users to upload HTML files via POST /uploads without type restrictions. Attackers can send the public GET /uploads/{path} URL to a signed-in victim, executing script in the application origin with the victim's access_token cookie, including administrators.
Predictions
Heuristic predictions, AS-IS, for prioritization only.
Mitigations
No mitigations published for this CVE yet.
The vendor-content worker queues fetches as references arrive (check back in a few minutes). Or — if you've already worked around this in production — publish your fix to the community-verified tier.
Propose a mitigation on Community Mitigations published via the community go through AI scoring + 2 human reviewers + 7-day silent objection window before landing here withsource_tier=community-verified.
References
- https://github.com/cheshire-cat-ai/core
- https://github.com/cheshire-cat-ai/core/blob/c22731e7009ac89835b1d7b1cabc5989d998ec3e/src/cat/scaffold/plugins/uploads/endpoints.py#L28-L96
- https://hackmd.io/@haind03/cheshire-cat-uploads-stored-html-same-origin-xss
- https://www.vulncheck.com/advisories/cheshire-cat-ai-core-through-2.0.23-stored-xss-via-uploads-plugin
CWEs
CWE-79
Community-verified mitigations for this CVE will appear above when contributors publish them.
Verify integrity in audit chain (admin only). AS-IS.