CVE-2026-4399General(1millionbot / millie_chatbot)

LOWCVSS 7.5 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch 1millionbot millie_chatbot systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Prompt injection vulnerability in 1millionbot Millie chatbot that occurs when a user manages to evade chat restrictions using Boolean prompt injection techniques (formulating a question in such a way that, upon receiving an affirmative response ('true'), the model executes the injected instruction), causing it to return prohibited information and information outside its intended context. Successful exploitation of this vulnerability could allow a malicious remote attacker to abuse the service for purposes other than those originally intended, or even execute out-of-context tasks using 1millionbot's resources and/or OpenAI's API key. This allows the attacker to evade the containment mechanisms implemented during LLM model training and obtain responses or chat behaviors that were originally restricted.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-77

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • millie_chatbot

Threat summary

  • Patch or workaround signal is available
  • 3 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 1 signal
  • General: 2 classified signals
  • Disclosure: 1 classified signal
  • Peaked 1d ago at 2 mentions (2026-03-31); latest day: 1
  • 3 total mentions across 2 days

Affected systems

Products
millie_chatbot

Deep dive

Activity timeline3 mentions / 2d
01122Mentions · 2026-03-31: 2Mentions · 2026-04-21: 1Patch / Workaround · 2026-04-21: 1Technical Details · 2026-03-31: 103-3104-21
Signal classification2 categories
General
266.7%
Disclosure
133.3%
Referenced assets2 URLs
Classification over time
DateTotalLabels
2026-03-312
Disclosure1General1
2026-04-211
General1
Full discourse3 posts
  • INCIBE-CERT@incibe_cert
    General

    ⚠️#INCIBEaviso | Múltiples vulnerabilidades en Millie chat de #1millionbot #CVE CVE-2026-4399 y CVE-2026-4400 https://www.incibe.es/incibe-cert/alerta-temprana/avisos/multiples-vulnerabilidades-en-millie-chat-de-1millionbot #AvisosDeSeguridad #TI #CNA #0day

    Post summary

    The advisory announces two CVEs (CVE-2026-4399 and CVE-2026-4400) affecting Millie chat of 1millionbot, but does not provide detailed technical information or evidence of exploitation.

    03020382
    42.6K followersView on X
  • R Chong@Muawin_AI
    General

    🚨 Visus-MCP v0.26.0 just dropped — now detects Boolean Logic Gates (IPI-021 / CVE-2026-4399) + risky MCP configs. While Anthropic calls STDIO RCE “expected behavior”, we ship real protection.

    Post summary

    Visus‑MCP v0.26.0 now detects the CVE‑2026‑4399 Boolean logic gate issue and highlights risky MCP configurations, providing a protective detection tool rather than a formal patch or exploit.

    1000032
  • CVE@CVEnew
    Disclosure

    CVE-2026-4399 Prompt injection vulnerability in 1millionbot Millie chatbot that occurs when a user manages to evade chat restrictions using Boolean prompt injection techniques (formu… https://www.cve.org/CVERecord?id=CVE-2026-4399

    Post summary

    The text announces CVE‑2026‑4399 as a prompt‑injection flaw in the 1millionbot Millie chatbot, detailing Boolean prompt injection methods but offering no PoC, exploit code, or patch information.

    00000135
    56.9K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
App1millionbotmillie_chatbot---

Explore more