Cross-site scripting in Apache Answer - CVE-2026-25688
Published: August 25, 2026
Vulnerability details
The vulnerability allows a remote attacker to execute arbitrary script code in the victim's browser.
The vulnerability exists due to improper neutralization of alternate xss syntax in AI answer rendering when rendering AI-generated response content in the browser. A remote attacker can craft malicious AI-generated content to execute arbitrary script code in the victim's browser.
User interaction is required to view the crafted content.