Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Thu, 12 Feb 2026 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Chattermate chattermate
|
|
| CPEs | cpe:2.3:a:chattermate:chattermate:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Chattermate chattermate
|
Mon, 26 Jan 2026 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 26 Jan 2026 12:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Chattermate
Chattermate chattermate.chat |
|
| Vendors & Products |
Chattermate
Chattermate chattermate.chat |
Sat, 24 Jan 2026 00:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | ChatterMate is a no-code AI chatbot agent framework. In versions 1.0.8 and below, the chatbot accepts and executes malicious HTML/JavaScript payloads when supplied as chat input. Specifically, an <iframe> payload containing a javascript: URI can be processed and executed in the browser context. This allows access to sensitive client-side data such as localStorage tokens and cookies, resulting in client-side injection. This issue has been fixed in version 1.0.9. | |
| Title | ChatterMate has Stored Cross-Site Scripting (XSS) via Chatbot Input Execution | |
| Weaknesses | CWE-79 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-01-26T16:17:53.948Z
Reserved: 2026-01-22T18:19:49.172Z
Link: CVE-2026-24399
Updated: 2026-01-26T16:15:52.860Z
Status : Analyzed
Published: 2026-01-24T01:15:50.393
Modified: 2026-02-12T16:05:57.580
Link: CVE-2026-24399
No data.
OpenCVE Enrichment
Updated: 2026-04-18T03:15:35Z