CyberRota Analysis
AI-GeneratedAix-DB versions up to 1.2.4 are vulnerable due to improper sanitization of markdown content rendered with raw HTML in v-html bindings, enabling stored cross-site scripting (XSS) attacks. This vulnerability allows attackers to inject malicious HTML and JavaScript into chat responses, skill descriptions, or knowledge messages, which can execute in users' browsers. Organizations utilizing affected Java products should prioritize remediation to protect against potential exploitation and user data compromise.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
Aix-DB through 1.2.4 renders markdown with raw HTML enabled into v-html bindings without sanitization, allowing stored cross-site scripting attacks. Attackers can inject malicious HTML and JavaScript through markdown content in chat responses, skill descriptions, or knowledge messages that execute in users' browsers when viewed.