Search Results (2 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2026-108725 1 Cheshire-cat-ai 1 Core 2026-10-11 5.4 Medium
Cheshire Cat AI core through 2.0.23 contains a stored cross-site scripting vulnerability in the uploads plugin that allows authenticated users to upload HTML files via POST /uploads without type restrictions. Attackers can send the public GET /uploads/{path} URL to a signed-in victim, executing script in the application origin with the victim's access_token cookie, including administrators.
CVE-2026-85093 1 Cheshire-cat-ai 1 Core 2026-09-03 6.5 Medium
Cheshire Cat AI's GET /memory/collections/{collection_id}/points endpoint fails to apply per-user filtering when retrieving episodic memory points. Authenticated attackers with MEMORY:READ permission can retrieve all users' stored conversation messages and personal data by paginating through the collection using the offset cursor.