Aix-DB through 1.2.4 renders markdown with raw HTML enabled into v-html bindings without sanitization, allowing stored cross-site scripting attacks. Attackers can inject malicious HTML and JavaScript through markdown content in chat responses, skill descriptions, or knowledge messages that execute in users' browsers when viewed.
History

Wed, 02 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 31 Aug 2026 12:45:00 +0000

Type Values Removed Values Added
First Time appeared Apconw
Apconw aix-db
Vendors & Products Apconw
Apconw aix-db

Mon, 31 Aug 2026 11:00:00 +0000

Type Values Removed Values Added
Description Aix-DB through 1.2.4 renders markdown with raw HTML enabled into v-html bindings without sanitization, allowing stored cross-site scripting attacks. Attackers can inject malicious HTML and JavaScript through markdown content in chat responses, skill descriptions, or knowledge messages that execute in users' browsers when viewed.
Title Aix-DB through 1.2.4 Stored Cross-Site Scripting via Markdown
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 5.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N'}

cvssV4_0

{'score': 5.1, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published: 2026-08-31T10:51:06.572Z

Updated: 2026-09-02T15:38:10.814Z

Reserved: 2026-08-31T08:38:43.269Z

Link: CVE-2026-82881

cve-icon Vulnrichment

Updated: 2026-09-02T15:37:48.396Z

cve-icon NVD

Status : Deferred

Published: 2026-08-31T11:16:43.247

Modified: 2026-09-08T20:18:59.270

Link: CVE-2026-82881

cve-icon Redhat

No data.