Sunday, 13 September 2026
8 agent hacks today 7 vs yesterday (1)

ChatterMate AI chatbot XSS via chat input exposes tokens (CVE-2026-24399)

ChatterMate, a no-code AI chatbot agent framework, accepted and executed malicious HTML/JavaScript supplied as chat input in versions 1.0.8 and below, including an <iframe> with a javascript: URI, allowing access to client-side data such as localStorage tokens and cookies. The issue was fixed in version 1.0.9.

Disclosed 24 January 2026 · Record updated 13 September 2026

Impact

Client-side injection allowing attackers to access sensitive browser data such as localStorage tokens and cookies in affected chatbot deployments.

Our coverage

No articles linked to this incident yet.

Sources

  1. nvd.nist.govhttps://nvd.nist.gov/vuln/detail/CVE-2026-24399