VYPR
Medium severity6.1NVD Advisory· Published Jun 9, 2026· Updated Jun 10, 2026

CVE-2026-25688

CVE-2026-25688

Description

Improper Neutralization of Alternate XSS Syntax vulnerability in Apache Answer.

This issue affects Apache Answer: through 2.0.0.

AI-generated response content was rendered in the browser without proper sanitization, allowing malicious scripts to be executed when the content was viewed. Users are recommended to upgrade to version 2.0.1, which fixes the issue.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

2
  • Apache/Answer2 versions
    cpe:2.3:a:apache:answer:*:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:a:apache:answer:*:*:*:*:*:*:*:*range: <2.0.1
    • (no CPE)range: <=2.0.0

Patches

Vulnerability mechanics

References

2

News mentions

1