PT-2026-96064 · Unknown · 1Millionbot Ai Chat Platform
CVE-2026-91921
·
Published
2026-09-21
·
Updated
2026-09-21
CVSS v4.0
5.1
Medium
| Vector | AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:L/SA:N |
Name of the Vulnerable Software and Affected Versions
1millionbot AI Chat Platform (affected versions not specified)
Description
Inadequate input sanitization in the client-side rendering engine allows an unauthenticated remote user to execute Cross-Site Scripting (XSS). By sending messages containing Markdown syntax and specific unsanitized content blocks, an attacker can cause external hyperlinks to be rendered in the web interface. The impact is restricted to the user's own interactive session, with no identified compromise of internal infrastructure, administrative panels, or third-party data.
Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
1Millionbot Ai Chat Platform