Stored Cross-Site Scripting Vulnerability in Aix-DB by Apconw
CVE-2026-82881
5.1MEDIUM
What is CVE-2026-82881?
A vulnerability in Aix-DB, present in versions up to 1.2.4, allows attackers to perform stored cross-site scripting attacks by leveraging raw HTML enabled in markdown content. This issue arises when user-generated markdown in chat responses, skill descriptions, or knowledge messages is rendered through v-html bindings without sufficient sanitization. As a result, malicious HTML and JavaScript can be injected, which then executes in the browsers of users who view this compromised content, posing significant security risks.
Affected Version(s)
Aix-DB 0 <= 1.2.4
Aix-DB b568a0f3b18ecead9f7d38bb78017f664d54a1a9
