{"id":"CVE-2025-8848","title":"A vulnerability in danny-avila/librechat version 0.7.9 allows for HTML injection via the Accept-Language header","summary":"A vulnerability in danny-avila/librechat version 0.7.9 allows for HTML injection via the Accept-Language header. When a logged-in user sends an HTTP GET request with a crafted Accept-Language header, arbitrary HTML can be injected into t…","severity":"medium","cvss":5.4,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N","cwe":["CWE-94","CWE-79"],"vendor":"librechat","product":"librechat","affected":["librechat = 0.7.9"],"published":"2025-10-22","updated":"2026-10-08","sourceUpdated":"2026-10-08T11:10:00.250","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2025-8848","references":[{"url":"https://huntr.com/bounties/a05ebc1f-882a-4adc-b178-d3cefa4b730e","label":"security@huntr.dev"}],"tags":["nvd","exploit-available"],"epss":0.00453,"epssPercentile":0.37301,"exploits":{"nuclei":["CVE-2025-8848"],"checkedAt":"2026-10-08T11:32:03.415Z"},"exploitAvailable":true,"ingestedAt":"2026-10-08T11:31:27.491Z","slug":"CVE-2025-8848","body":"## Overview\n\nA vulnerability in danny-avila/librechat version 0.7.9 allows for HTML injection via the Accept-Language header. When a logged-in user sends an HTTP GET request with a crafted Accept-Language header, arbitrary HTML can be injected into the <html lang=\"\"> tag of the response. This can lead to potential security risks such as cross-site scripting (XSS) attacks.\n\n## Affected\n\n- `librechat = 0.7.9`\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"twilight","depthScore":42,"depthScoreParts":{"impact":29.7,"likelihood":0.1,"exploitation":12,"ransomware":0},"changes":[]}