CVE-2026-21832 PUBLISHED

HCL AION is affected by multiple security vulnerabilities.

Assigner: HCL
Reserved: 05.01.2026 Published: 13.08.2026 Updated: 13.08.2026

HCL AION is affected by a vulnerability where indirect prompt injection can lead to HTML injection in rendered output. Injected markup may be displayed to users, potentially resulting in unintended behavior or security impact under certain conditions.

Metrics

CVSS Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
CVSS Score: 4.3

Product Status

Vendor HCL Software
Product AION
Versions Default: unaffected
  • Version v2.5.0 is affected

References

Problem Types

  • CWE-1427 Improper Neutralization of Input Used for LLM Prompting CWE