Stored Cross-Site Scripting Vulnerability in Aix-DB by Apconw
CVE-2026-82881

5.1MEDIUM

Key Information:

Vendor

Apconw

Status
Vendor
CVE Published:
31 August 2026

What is CVE-2026-82881?

A vulnerability in Aix-DB, present in versions up to 1.2.4, allows attackers to perform stored cross-site scripting attacks by leveraging raw HTML enabled in markdown content. This issue arises when user-generated markdown in chat responses, skill descriptions, or knowledge messages is rendered through v-html bindings without sufficient sanitization. As a result, malicious HTML and JavaScript can be injected, which then executes in the browsers of users who view this compromised content, posing significant security risks.

Affected Version(s)

Aix-DB 0 <= 1.2.4

Aix-DB b568a0f3b18ecead9f7d38bb78017f664d54a1a9

References

CVSS V4

Score:
5.1
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Yu Sun
.