Tuesday, December 16, 2025

blackbox.ai stored XSS vulnerability

I found a prompt injection stored cross-site-scripting vulnerability in blackbox.ai which can allow an attacker to inject XSS code then share it to a victim to steal it's cookies while victim's browser currently authenticated to https://www.blackbox.ai.  

https://www.blackbox.ai/share/576066de-6268-4dbd-8c51-3dd509eadba4




I reported this security vulnerability to gisele@blackbox.ai on October 2, 2025. They initially responded and said they would look into it. However, despite a series of consistent follow-ups, never heard from them again.

[Update]
The issue has been fixed, waiting for more details.

October 2, 2025 – Initial submission sent
November 1, 2025 – Follow-up made
January 4, 2026 – Received confirmation (Request #136) that the report is under review
January–February 2026 – Security vulnerability was remediated during this period
February 12, 2026 – Follow-up sent noting that the issue had already been fixed; Asking for the commit details as requested by mitre.org for cve issuance; But no response received from blackbox.ai
March 13, 2026 – Follow-up sent requesting details for CVE assignment; new ticket issued (Request #4908)
March 15, 2026 – No response
March 20, 2026 – No response
March 27, 2026 – No response
April 3, 2026 – No response
April 8, 2026 – Most recent follow-up sent; no response received




No comments:

Post a Comment