Impact
The vulnerability is an indirect prompt injection flaw that permits attackers to insert arbitrary HTML markup into the rendered output of HCL AION. When the injected markup is displayed to users, it may lead to unintended behavior such as UI manipulation or potential compromise of sensitive information. The weakness is a form of content injection represented by CWE‑1427.
Affected Systems
The flaw affects the HCL Software AION platform. No specific product versions are identified in the advisory, so all deployments of AION should be reviewed for the presence of the fix.
Risk and Exploitability
The CVSS score of 4.3 indicates moderate severity. No EPSS score is available and the vulnerability is not listed in the CISA KEV catalog. Attackers would need to supply a prompt containing malicious HTML; the exact attack vector is not detailed, so the risk is considered moderate. The lack of publicly known exploits suggests the threat remains primarily theoretical at this time.
OpenCVE Enrichment