CVE-2026-27068: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Ryan Howard Website LLMs.txt website-llms-txt allows Reflected XSS.This issue affects Website L...

Added to the CISA Known Exploited Vulnerabilities catalog on 19 Mar 2026. Vendor: AI/ML. Product: LLM.

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Ryan Howard Website LLMs.txt website-llms-txt allows Reflected XSS.This issue affects Website LLMs.txt: from n/a through <= 8.2.6.

Required action: Review and patch if applicable to your AI infrastructure.