CVE-2026-105798

Source
https://cve.org/CVERecord?id=CVE-2026-105798
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-105798.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-105798
Aliases
  • GHSA-qwcw-r653-j8c6
Published
2026-10-06T14:25:39Z
Modified
2026-10-08T02:50:43Z
Severity
  • 8.7 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N CVSS Calculator
Summary
SimpleChat: Stored XSS via group document filename in inline onclick handler
Details

SimpleChat is a secure AI conversation application with personal and group workspaces for document-grounded interactions. Prior to 0.261.029, POST /api/group_documents/upload stores an attacker-controlled group document filename that group_workspaces.html later interpolates into inline Share event handlers. The escapeGroupHtml function leaves apostrophes unchanged, while escapeHtml produces an HTML entity that the browser decodes before JavaScript evaluation, so either path permits the filename to terminate the handler string. An authenticated group Owner, Admin, or DocumentManager can persist script that executes in the SimpleChat origin when another group member clicks Share, allowing access to victim-visible data and actions with the victim session. This issue is fixed in version 0.261.029.

Database specific
{
    "cna_assigner": "GitHub_M",
    "cwe_ids": [
        "CWE-79"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/105xxx/CVE-2026-105798.json",
    "unresolved_ranges": [
        {
            "extracted_events": [
                {
                    "fixed": "0.261.029"
                }
            ],
            "source": "AFFECTED_FIELD"
        }
    ]
}
References

Affected packages

Git / github.com/microsoft/simplechat

Affected ranges

Type
GIT
Repo
https://github.com/microsoft/simplechat
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed
Database specific
Show details
{
    "source": "REFERENCES"
}

Affected versions

0.*
0.190.1
0.190.3
0.202.37
0.202.41
v0.*
v0.179.group_documents.13
v0.185.0
v0.185.1
v0.191.0
v0.196.9
v0.199.3
v0.201.5
v0.202.21
v0.203.15
v0.203.16
v0.212.078
v0.212.079
v0.212.091
v0.213.001
v0.213.003
v0.214.001
v0.215.34
v0.215.35
v0.215.36
v0.215.37
v0.215.38
v0.229.001

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-105798.json"