Impact
The vulnerability is a client‑side Cross‑Site Scripting flaw caused by insufficient sanitisation of Markdown messages in the rendering engine. An unauthenticated user can embed malicious links or scripts that will be rendered when the message is displayed. The flaw allows injection of arbitrary HTML or JavaScript into the attacker’s own view but does not provide direct access to the backend or other users' data.
Affected Systems
1millionbot’s AI Chatbot Platform (SaaS) across all releases built before the CVE was disclosed, as identified by the product’s CPE value indicating all earlier versions.
Risk and Exploitability
With a CVSS score of 5.1 the vulnerability is rated moderate. No EPSS score is available and the issue is not listed in CISA’s KEV catalog, suggesting no current widespread exploitation. The most likely attack vector is through the public web interface, where an unauthenticated user can post a crafted message. Because the impact is confined to the user’s own session and requires no privileged access, the overall risk to the organisational infrastructure is limited.
OpenCVE Enrichment