CVE-2026-91921

LOWCVSS 5.1 · MEDIUM

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Cross-Site Scripting (XSS) vulnerability due to inadequate input sanitisation in the client-side rendering engine of the 1millionbot AI Chat Platform. An unauthenticated remote user could cause external hyperlinks to be rendered in the web interface by sending messages containing Markdown syntax and certain unsanitised content blocks. The impact is limited to the user’s own interactive session; no compromise of internal infrastructure, access to third-party data or impact on administrative panels has been identified.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-79

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Threat summary

  • 1 mentions across 1 observed day

What's happening

  • 1 total mentions across 1 day

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-09-21: 109-21
Referenced assets1 URL
Full discourse1 post
  • INCIBE-CERT@incibe_cert

    ⚠️#INCIBEaviso | Cross-Site Scripting (XSS) en AI Chatbot Platform de #1millionbot #CVE CVE-2026-91921 https://www.incibe.es/incibe-cert/alerta-temprana/avisos/cross-site-scripting-xss-en-ai-chatbot-platform-de-1millionbot #AvisosDeSeguridad #TI #CNA #0day

    0000030
    52 followersView on X

Explore more