---
id: CVE-2025-8349
title: Cross-site Scripting (XSS) stored vulnerability in Tawk Live Chat
summary: >-
  Cross-site Scripting (XSS) stored vulnerability in Tawk Live Chat. This
  vulnerability allows an attacker to execute JavaScript code in the victim's
  browser by uploading a malicious PDF with JavaScript payload through the
  chatbot. The PDF…
severity: none
cwe:
  - CWE-79
published: '2025-10-20'
updated: '2026-10-08'
sourceUpdated: '2026-10-08T22:10:00.563'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-8349'
references:
  - url: >-
      https://www.incibe.es/en/incibe-cert/notices/aviso/cross-site-scripting-xss-stored-tawk-live-chat
    label: cve-coordination@incibe.es
tags:
  - nvd
epss: 0.00533
epssPercentile: 0.43193
ingestedAt: '2026-10-08T22:11:53.816Z'
---

## Overview

Cross-site Scripting (XSS) stored vulnerability in Tawk Live Chat. This vulnerability allows an attacker to execute JavaScript code in the victim's browser by uploading a malicious PDF with JavaScript payload through the chatbot. The PDF is stored by the application and subsequently displayed without proper sanitisation when other users access it. This vulnerability can be exploited to steal sensitive user data, such as session cookies, or to perform actions on behalf of the user.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
