chattermate CVE Vulnerabilities & CVE List (1)

Products (CPE): — CVEs: 1

chattermate vulnerability overview

This page aggregates publicly disclosed CVE and security risk information related to chattermate, with CVSS, EPSS, publication dates, and vulnerability intelligence data to help assess potential risk and remediation priority.

Vulnerability distribution trend (last 24 months)

Showing 11 of 1 CVEs
«« First « Prev Page 1 / 1 Next »
CVE Summary Source Max CVSS EPSS % Published Updated
CVE-2026-24399 ChatterMate is a no-code AI chatbot agent framework. In versions 1.0.8 and below, the chatbot accepts and executes malicious HTML/JavaScript payloads when supplied as chat input. Specifically, an <iframe> payload containing a javascript: URI can be processed and executed in the browser context. This allows access to sensitive client-side data such as localStorage tokens and cookies, resulting in client-side injection. This issue has been fixed in version 1.0.9. [email protected] 9.3 0.30% 2026-01-23 2026-06-17
«« First « Prev Page 1 / 1 Next »
cvelogic Threat Intelligence