ChatterMate AI chatbot XSS via chat input exposes tokens (CVE-2026-24399)
ChatterMate, a no-code AI chatbot agent framework, accepted and executed malicious HTML/JavaScript supplied as chat input in versions 1.0.8 and below, including an <iframe> with a javascript: URI, allowing access to client-side data such as localStorage tokens and cookies. The issue was fixed in version 1.0.9.
Disclosed 24 January 2026 · Record updated 13 September 2026
Impact
Client-side injection allowing attackers to access sensitive browser data such as localStorage tokens and cookies in affected chatbot deployments.
Our coverage
No articles linked to this incident yet.
Sources
- nvd.nist.govhttps://nvd.nist.gov/vuln/detail/CVE-2026-24399
