Impact
Aix‑DB up to version 1.2.4 renders markdown that contains raw HTML directly into v-html bindings without sanitization. This allows an attacker to embed malicious HTML and JavaScript in markdown content such as chat responses, skill descriptions, or knowledge messages. When another user views the rendered content in a browser, the injected script executes, potentially hijacking the session, stealing credentials, or delivering further phishing or malicious payloads.
Affected Systems
The vulnerability affects the Aix‑DB application supplied by apconw, specifically version 1.2.4 and earlier. Versions beyond 1.2.4 have reportedly addressed the issue; however, any instance that still runs 1.2.4 or a previous release remains at risk.
Risk and Exploitability
With a CVSS score of 5.1, the severity is medium; the exploit probability is not quantified by EPSS, and the vulnerability is not listed in the CISA KEV catalog. An attacker must have the ability to submit markdown content (e.g., via chat, skill creation, or knowledge base entry). Once the content is stored, any user who views it in a browser will be affected, giving attackers a broad window for executing client‑side attacks. The attack vector is therefore likely an insider or external user with write privileges to the affected content areas.
OpenCVE Enrichment