CVE-2026-82881

Summary

Aix-DB through 1.2.4 renders markdown with raw HTML enabled into v-html bindings without sanitization, allowing stored cross-site scripting attacks. Attackers can inject malicious HTML and JavaScript through markdown content in chat responses, skill descriptions, or knowledge messages that execute in users' browsers when viewed.

Affected Software

VendorProductVersion RangeStatus
apconwAix-DB0 <= 1.2.4affected
apconwAix-DBb568a0f3b18ecead9f7d38bb78017f664d54a1a9unaffected

Weaknesses

  • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

References