A cross-site scripting (XSS) vulnerability existed due to improper sanitization of AI prompt responses. Attackers could inject HTML or script into pages viewed by other users, potentially leading to session theft or UI manipulation