What happened
POST /api/group_documents/upload stores an attacker-controlled group document filename that is later interpolated into inline Share event handlers without safely encoding apostrophes (both escaping paths permit terminating the handler string). An authenticated group Owner/Admin/DocumentManager can persist script that executes in the SimpleChat origin when another group member clicks Share, gaining victim-visible data and victim-session actions. Fixed in 0.261.029.
Why it matters
In a document-grounded AI workspace, the stored script runs inside the SimpleChat origin session of other users, so an attacker group member can read other users' RAG/chat data and act with their session — a cross-user pivot within the AI conversation platform.
Attack vector
Upload a group document with a crafted filename containing payload that escapes the inline Share event handler; script fires when a victim clicks Share.
Affected systems
Microsoft SimpleChat < 0.261.029
Mitigation
Upgrade to SimpleChat 0.261.029; audit existing group-document filenames for payload characters.