CVE-2026-70331
Improper neutralization of input used for llm prompting in Microsoft Edge for iOS allows an unauthorized attacker to perform spoofing over a network.
Scoring
- Severity
- MEDIUM
- CVSS base score
- 5.4
- CVSS vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N/E:U/RL:O/RC:C
- EPSS probability
- 0.29%
- CWE
- CWE-1427
- Published
- 2026-08-28
- Last modified
- 2026-09-09
Affected products
- Microsoft Microsoft Edge (Chromium-based)
- Microsoft Microsoft Edge for iOS
Weakness type
Related vulnerabilities
- CVE-2026-78379 — Consent bypass in python_repl tool via batch kwargs forwarding in Amazon Strands Agents Tools
- CVE-2026-75130 — Context7 2.1.2 Prompt Injection via Custom AI Instructions
- CVE-2026-21832 — HCL AION is affected by multiple security vulnerabilities.
- CVE-2026-18733 — Prompt injection bypasses shell tool consent gate in Strands Agents Tools
- CVE-2026-15077 — Improper Neutralization of Input Used for LLM Prompting in GitLab
- CVE-2026-46580 — In Eclipse Theia versions prior to 1.71.0, files matching the pattern .prompts/*.prompttemplate in...
- CVE-2026-44688 — In Eclipse Theia versions prior to 1.71.0, the AI chat agent processed workspace file and directory...
- CVE-2026-44717 — MCP Calculate Server: Prompt Injection to RCE