I found a prompt injection stored cross-site-scripting vulnerability in blackbox.ai which can allow an attacker to inject XSS code then share it to a victim to steal it's cookies while victim's browser currently authenticated to https://www.blackbox.ai.
https://www.blackbox.ai/share/576066de-6268-4dbd-8c51-3dd509eadba4
[Update]
The issue has been fixed, waiting for more details.
The issue has been fixed, waiting for more details.
October 2, 2025 – Initial submission sent
November 1, 2025 – Follow-up made
January 4, 2026 – Received confirmation (Request #136) that the report is under review
January–February 2026 – Security vulnerability was remediated during this period
February 12, 2026 – Follow-up sent noting that the issue had already been fixed; Asking for the commit details as requested by mitre.org for cve issuance; But no response received from blackbox.ai
March 13, 2026 – Follow-up sent requesting details for CVE assignment; new ticket issued (Request #4908)
March 15, 2026 – No response
March 20, 2026 – No response
March 27, 2026 – No response
April 3, 2026 – No response
April 8, 2026 – Most recent follow-up sent; no response received
No comments:
Post a Comment