Vulnerability  ·  2026-04-14

CVE-2026-39426: Stored XSS in LLM Application Frontend (MdRenderer.vue)

VulnerabilityHigh impactCVE-2026-39426
Versions ≤2.7.1 parse custom <iframe_render> tags from LLM responses or Application Prologue configurations, bypassing Markdown sanitisation and enabling Stored XSS with session hijacking and sensitive data exposure.
Network, low complexity. Attacker supplies malicious content via LLM output or configuration that the renderer parses unsanitised.
LLM application versions ≤2.7.1. Fixed in 2.8.0.
Upgrade to 2.8.0+. Enforce strict CSP. Sanitise all user-controllable content before rendering.
Sources
THREATINT CVE entry
See this in the live feed Explore related AI security and governance findings — updated every morning.
Open the feed →