CVE-2026-4399: Prompt injection vulnerability in 1millionbot Millie chatbot that occurs when a user manages to evade chat restrictions using Boolean prompt injection techniques (formulating a question in such a w...

Added to the CISA Known Exploited Vulnerabilities catalog on 31 Mar 2026. Vendor: AI/ML. Product: LLM. CVSS score: 7.5.

Prompt injection vulnerability in 1millionbot Millie chatbot that occurs when a user manages to evade chat restrictions using Boolean prompt injection techniques (formulating a question in such a way that, upon receiving an affirmative response ('true'), the model executes the injected instructio...

Required action: Review and patch if applicable to your AI infrastructure.