MEDIUM
1millionbot
CVE published 2026-09-21
CVE-2026-91921
CVE-2026-91921 is a Cross-Site Scripting (XSS) vulnerability in the 1millionbot AI Chat Platform due to inadequate input sanitization. An unauthenticated remote user can cause external hyperlinks to be rendered in the web interface by sending messages with Markdown syntax and certain unsanitized content blocks. The impact is limited to the user's own interactive session.