EUVD Vulnerability Catalog

EUVD-2026-83880

Severity: MEDIUM Base Score: 5.1 CVSS Version: 4.0

Vulnerability Description

Cross-Site Scripting (XSS) vulnerability due to inadequate input sanitisation in the client-side rendering engine of the 1millionbot AI Chat Platform. An unauthenticated remote user could cause external hyperlinks to be rendered in the web interface by sending messages containing Markdown syntax and certain unsanitised content blocks. The impact is limited to the user’s own interactive session; no compromise of internal infrastructure, access to third-party data or impact on administrative panels has been identified.

CVSS Vector Analysis

Below is the complete, human-readable breakdown of the CVSS metric string: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:L/SA:N

Attack Vector (AV): Network
Attack Complexity (AC): Low
Attack Requirements (AT): None
Privileges Required (PR): None
User Interaction (UI): Active
Vulnerability Confidentiality Impact (VC): None
Vulnerability Integrity Impact (VI): Low
Vulnerability Availability Impact (VA): None
Subsequent Confidentiality Impact (SC): None
Subsequent Integrity Impact (SI): Low
Subsequent Availability Impact (SA): None

Affected Vendors & Systems

Vendor 1millionbot

References & Advisory Links

Metadata Profile

Database Authority

European Union Agency for Cybersecurity (ENISA) EUVD

Assigner

INCIBE

EPSS Probability

0

Known Aliases
CVE-2026-91921
Published On

2026-09-21

Last Updated

2026-09-21