VulnerabilityAnalyzed
CVE-2026-25688
Improper Neutralization of Alternate XSS Syntax vulnerability in Apache Answer.
MEDIUM 6.1EPSS 0.41%
Does this matter?
Lower severity and a low EPSS score (0.41%). Track it; it rarely justifies an emergency change on its own.
Description
Improper Neutralization of Alternate XSS Syntax vulnerability in Apache Answer. This issue affects Apache Answer: through 2.0.0. AI-generated response content was rendered in the browser without proper sanitization, allowing malicious scripts to be executed when the content was viewed. Users are recommended to upgrade to version 2.0.1, which fixes the issue.
- CVSS 3.1
- 6.1 MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
- EPSS
- 0.41% probability · 34th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-87
- Affected
- apache/answer
- Source
- security@apache.org
References
- https://lists.apache.org/thread/x42joj43rqb38ms5q60f7bgq3qbo7t5qMailing List, Vendor Advisory
- http://www.openwall.com/lists/oss-security/2026/06/09/7Mailing List, Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.