PT-2026-29219 · 1Millionbot+1 · 1Millionbot Millie+1

Published

2026-03-31

·

Updated

2026-04-21

·

CVE-2026-4399

CVSS v4.0

8.7

High

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions 1millionbot Millie chatbot (affected versions not specified)
Description A prompt injection issue exists in the 1millionbot Millie chatbot. This occurs when a user bypasses chat restrictions using Boolean prompt injection techniques, constructing a question to elicit an affirmative ('true') response that triggers the execution of injected instructions. Successful exploitation allows a remote attacker to misuse the service, obtain prohibited information, or execute unintended tasks leveraging 1millionbot’s resources and/or the OpenAI API key. This bypasses containment mechanisms during LLM model training, enabling restricted responses or behaviors. The API key used by 1millionbot could be compromised.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

RCE

Command Injection

Weakness Enumeration

Related Identifiers

CVE-2026-4399

Affected Products

1Millionbot Millie
Openai Api