Vulnerability  ·  2026-10-07

Microsoft SimpleChat stored XSS via group document filename in inline Share handler

VulnerabilityMedium impactGlobalCVE-2026-105798
POST /api/group_documents/upload stores an attacker-controlled group document filename that is later interpolated into inline Share event handlers without safely encoding apostrophes (both escaping paths permit terminating the handler string). An authenticated group Owner/Admin/DocumentManager can persist script that executes in the SimpleChat origin when another group member clicks Share, gaining victim-visible data and victim-session actions. Fixed in 0.261.029.
In a document-grounded AI workspace, the stored script runs inside the SimpleChat origin session of other users, so an attacker group member can read other users' RAG/chat data and act with their session — a cross-user pivot within the AI conversation platform.
Upload a group document with a crafted filename containing payload that escapes the inline Share event handler; script fires when a victim clicks Share.
Microsoft SimpleChat < 0.261.029
Upgrade to SimpleChat 0.261.029; audit existing group-document filenames for payload characters.
NVD CVE-2026-105798GitHub advisory GHSA-qwcw-r653-j8c6NVD CVE-2026-105797
See this in the live feed Explore related AI security and governance findings — updated every morning.
Open the feed →