PT-2025-43144 · Librechat · Librechat

Published

2025-10-22

·

Updated

2025-12-31

·

CVE-2025-8848

CVSS v2.0

5.5

Medium

VectorAV:N/AC:L/Au:S/C:P/I:P/A:N
Name of the Vulnerable Software and Affected Versions librechat version 0.7.9
Description A flaw exists in danny-avila/librechat version 0.7.9 that permits HTML injection through the Accept-Language header. A logged-in user sending an HTTP GET request with a specially crafted Accept-Language header can inject arbitrary HTML into the tag of the response. This could potentially lead to cross-site scripting (XSS) attacks.
Recommendations Update to a newer version that contains a fix for this vulnerability.

Exploit

Fix

XSS

Code Injection

Weakness Enumeration

Related Identifiers

BDU:2026-07575
CVE-2025-8848

Affected Products

Librechat