Weeks apart, at two unrelated companies, Escape’s AI pentesting agent found the same stored XSS. Both had shipped a customer-facing chat where the model emits Markdown and the frontend renders it with raw HTML enabled and no sanitizer, so anything the model can be made to say executes
First seen on securityboulevard.com
Jump to article: securityboulevard.com/2026/08/escape-found-the-same-xss-in-two-ai-chatboxes-the-vulnerability-was-in-the-markdown-renderer/
![]()

