PT-2026-96064 · Unknown · 1Millionbot Ai Chat Platform

CVE-2026-91921

·

Published

2026-09-21

·

Updated

2026-09-21

CVSS v4.0

5.1

Medium

VectorAV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:L/SA:N
Name of the Vulnerable Software and Affected Versions 1millionbot AI Chat Platform (affected versions not specified)
Description Inadequate input sanitization in the client-side rendering engine allows an unauthenticated remote user to execute Cross-Site Scripting (XSS). By sending messages containing Markdown syntax and specific unsanitized content blocks, an attacker can cause external hyperlinks to be rendered in the web interface. The impact is restricted to the user's own interactive session, with no identified compromise of internal infrastructure, administrative panels, or third-party data.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-91921

Affected Products

1Millionbot Ai Chat Platform