{"data":{"id":"34d53460-52c5-46dd-9064-9a77d7d6810d","title":"CVE-2026-63216: Zammad is a web based open source helpdesk/customer support system. Prior to 7.1.2, unsanitized option labels are render","summary":"Zammad, a web-based helpdesk system, has a vulnerability in versions before 7.1.2 where option labels in AI Agent configuration dialogs are not properly sanitized (cleaned of malicious code). An attacker can inject malicious HTML and JavaScript by controlling an option label, such as through a user name or custom attribute, and this malicious code runs in the browser of any admin or agent who views the affected configuration. This is a type of code injection attack where unsafe user input is directly displayed without protection.","solution":"Update to version 7.1.2 or later, where this issue is fixed.","labels":["security"],"sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-63216","publishedAt":"2026-09-25T19:17:55.517Z","cveId":"CVE-2026-63216","cweIds":["CWE-80"],"cvssScore":null,"cvssSeverity":null,"severity":"high","attackType":["prompt_injection"],"issueType":"vulnerability","affectedPackages":null,"affectedVendors":[],"affectedVendorsRaw":["Zammad"],"classifierModel":"claude-haiku-4-5-20251001","classifierPromptVersion":"v3","cvssVector":null,"attackVector":null,"attackComplexity":null,"privilegesRequired":null,"userInteraction":null,"exploitMaturity":"unknown","epssScore":0,"patchAvailable":null,"disclosureDate":"2026-09-25T19:17:55.517Z","capecIds":null,"crossRefCount":0,"attackSophistication":"trivial","impactType":["integrity"],"aiComponentTargeted":"agent","llmSpecific":false,"classifierConfidence":0.85,"researchCategory":null,"atlasIds":["AML.T0051"]}}