MEDIUM
cheshire-cat-ai
CVE published 2026-10-11
CVE-2026-108725
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-10-11T12:19:34.601Z and has not been modified since then. The Cheshire Cat AI core through 2.0.23 contains a stored cross-site scripting vulnerability in the uploads plugin, allowing authenticated users to upload HTML files via POST /uploads without type restrictions. Attackers can exploit this by send [truncated]