Cross-Site Scripting Vulnerability in 1millionbot AI Chat Platform
CVE-2026-91921

5.1MEDIUM

Key Information:

Vendor
CVE Published:
21 September 2026

What is CVE-2026-91921?

The 1millionbot AI Chat Platform is susceptible to a Cross-Site Scripting (XSS) vulnerability due to insufficient input sanitization within its client-side rendering engine. This flaw allows unauthenticated remote users to send messages containing Markdown syntax with certain unsanitized content blocks, leading to the rendering of external hyperlinks in the web interface. While this vulnerability affects only the user’s interactive session, it does not compromise internal infrastructure, access to third-party data, or administrative panels.

Affected Version(s)

AI Chatbot Platform (SaaS) de 1millionbot. Version prior to CVE publication

References

CVSS V4

Score:
5.1
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Alejandro González Martínez
.