Improper Neutralization Vulnerability in Apache Answer Affects Multiple Users
CVE-2026-25688

6.1MEDIUM

Key Information:

Vendor

Apache

Vendor
CVE Published:
9 June 2026

What is CVE-2026-25688?

A significant vulnerability in Apache Answer allows for the execution of malicious scripts due to improper sanitization of AI-generated content. When users view the affected output, unfiltered scripts can be launched, leading to potential security breaches. To mitigate this risk, users are strongly advised to upgrade to version 2.0.1, which addresses the flaw and enhances overall security.

Affected Version(s)

Apache Answer 0 <= 2.0.0

References

CVSS V3.1

Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Sho Odagiri
.