MEDIUMVulnerability

CVE-2026-82881

Aix-DB through 1.2.4 renders markdown with raw HTML enabled into v-html bindings without sanitization, allowing stored cross-site scripting attacks. Attackers can inject malicious HTML and JavaScript through markdown content in chat responses, skill descriptions, or knowledge messages that execute in users' browsers when viewed.

Properties

severity
MEDIUM
score
5.4
epss_score
0.00188
cve_id
CVE-2026-82881
vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
published_at
2026-08-31T11:16:43.247
last_modified
2026-09-02T16:17:27.250
epss_percentile
0.08479

Related Entities (3)

ENRICHED_BY (1)

[Source]FIRST EPSS

DESCRIBED_BY (1)

[Source]NVD

HAS_WEAKNESS (1)

[Weakness]Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Explore deeper with Ninja Signal's threat intelligence graph

CVE-2026-82881 — Ninja Signal Threat Intelligence | Ninja Signal