1millionbot operates a focused chatbot product portfolio, with vulnerabilities centered on the Millie chatbot platform and rooted in authorization and input-handling deficiencies. The recurring weakness classes—authorization bypass through user-controlled keys and improper command-injection neutralization—point to access-control and parsing risks inherent to conversational interfaces. Live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by 1millionbot over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-4399HIGH Prompt injection vulnerability in 1millionbot Millie chatbot that occurs when a user manages to evade chat restrictions using Boolean prompt injection techniques (formulating a que | Mar 31, 2026 | 7.5 | 26 | NO | NO |
CVE-2026-4400MEDIUM Insecure Direct Object Reference (IDOR) vulnerability in 1millionbot Millie chat that allows private conversations of other users being viewed by simply changing the conversation I | Mar 31, 2026 | 6.5 | 23 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by 1millionbot.
Media articles that mention a CVE ID that affects a product developed by 1millionbot — matched by CVE ID, not by vendor name.