SEPTEMBER 17, 2026
Live Feed
Back to database
Case File

CVE-2026-82881

MEDIUM · CVSS 5.4 EPSS 0.19% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-08-31 · Last synced 2026-09-17

CyberRota Analysis

AI-Generated

Aix-DB versions up to 1.2.4 are vulnerable due to improper sanitization of markdown content rendered with raw HTML in v-html bindings, enabling stored cross-site scripting (XSS) attacks. This vulnerability allows attackers to inject malicious HTML and JavaScript into chat responses, skill descriptions, or knowledge messages, which can execute in users' browsers. Organizations utilizing affected Java products should prioritize remediation to protect against potential exploitation and user data compromise.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-82881
Severity
MEDIUM
CVSS
5.4
EPSS
0.19%
Java

Original NVD Description

Aix-DB through 1.2.4 renders markdown with raw HTML enabled into v-html bindings without sanitization, allowing stored cross-site scripting attacks. Attackers can inject malicious HTML and JavaScript through markdown content in chat responses, skill descriptions, or knowledge messages that execute in users' browsers when viewed.