URL has been copied successfully!
Escape found the same XSS in two AI chatboxes. The vulnerability was in the Markdown renderer.
URL has been copied successfully!

Collecting Cyber-News from over 60 sources

Escape found the same XSS in two AI chatboxes. The vulnerability was in the Markdown renderer.

Weeks apart, at two unrelated companies, Escape’s AI pentesting agent found the same stored XSS. Both had shipped a customer-facing chat where the model emits Markdown and the frontend renders it with raw HTML enabled and no sanitizer, so anything the model can be made to say executes

First seen on securityboulevard.com

Jump to article: securityboulevard.com/2026/08/escape-found-the-same-xss-in-two-ai-chatboxes-the-vulnerability-was-in-the-markdown-renderer/

Loading

Share via Email
Share on Facebook
Tweet on X (Twitter)
Share on Whatsapp
Share on LinkedIn
Share on Xing
Copy link