CVE-2025-8848Medium· 5.4▾ TwilightPoC availableA vulnerability in danny-avila/librechat version 0.7.9 allows for HTML injection via the Accept-Language header. When a logged-in user sends an HTTP GET request with a crafted Accept-Language header, arbitrary HTML can be injected into t…
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 29.7 · likelihood 0.1 · exploitation 12
A public proof-of-concept already exists for this vulnerability — see Exploit availability below.
Public exploit / PoC code seen in 1 source. Availability, not in-the-wild use.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
0.5%
Nuclei ×1 (last check)
A vulnerability in danny-avila/librechat version 0.7.9 allows for HTML injection via the Accept-Language header. When a logged-in user sends an HTTP GET request with a crafted Accept-Language header, arbitrary HTML can be injected into the <html lang=""> tag of the response. This can lead to potential security risks such as cross-site scripting (XSS) attacks.
librechat = 0.7.9Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Connected by shared product, vendor, weakness, or advisory.
CVE-2025-66452Medium· 6.1LibreChat is a ChatGPT clone with additional features
CVE-2025-8849High· 7.5LibreChat version 0.7.9 is vulnerable to a Denial of Service (DoS) attack due to unbounded parameter values in the `/api/memories` endpoint
CVE-2025-8850High· 8.8In danny-avila/librechat version 0.7.9, there is an insecure API design issue in the 2-Factor Authentication (2FA) flow
CVE-2025-66450Medium· 5.4LibreChat is a ChatGPT clone with additional features
CVE-2025-66451Medium· 6.5LibreChat is a ChatGPT clone with additional features
CVE-2025-66201High· 8.1LibreChat is a ChatGPT clone with additional features