Cross-Site Scripting Vulnerability in 1millionbot AI Chat Platform
CVE-2026-91921
5.1MEDIUM
What is CVE-2026-91921?
The 1millionbot AI Chat Platform is susceptible to a Cross-Site Scripting (XSS) vulnerability due to insufficient input sanitization within its client-side rendering engine. This flaw allows unauthenticated remote users to send messages containing Markdown syntax with certain unsanitized content blocks, leading to the rendering of external hyperlinks in the web interface. While this vulnerability affects only the user’s interactive session, it does not compromise internal infrastructure, access to third-party data, or administrative panels.
Affected Version(s)
AI Chatbot Platform (SaaS) de 1millionbot. Version prior to CVE publication
