CVE-2026-21832: HCL AION is affected by a vulnerability where indirect prompt injection can lead to HTML injection in rendered output. I
Summary
HCL AION has a vulnerability where indirect prompt injection (tricking an AI by hiding malicious instructions in its input data) can lead to HTML injection (inserting harmful web code) in the output that users see. This could cause unintended behavior or security problems depending on how the system is used.
Vulnerability Details
4.3(medium)
EPSS: 0.0%
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
network
low
low
none
August 13, 2026
Classification
Taxonomy References
Affected Vendors
Related Issues
Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-21832
First tracked: August 13, 2026 at 02:08 PM
Classified by LLM (prompt v3) · confidence: 75%