CVE-2026-21832
4.3
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Summary
HCL AION is affected by a vulnerability where indirect prompt injection can lead to HTML injection in rendered output. Injected markup may be displayed to users, potentially resulting in unintended behavior or security impact under certain conditions.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| HCL Software | AION | v2.5.0 | affected |
Weaknesses
- CWE-1427: CWE-1427 Improper Neutralization of Input Used for LLM Prompting
ADP Enrichment
CISA ADP Vulnrichment
- SSVC:
- Exploitation: none
- Automatable: no
- Technical Impact: partial
References
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.