CVE-2025-8848: HTML Injection in Accept-Language Header in danny-avila/librechat
A vulnerability in danny-avila/librechat version 0.7.9 allows for HTML injection via the Accept-Language header. When a logged-in user sends an HTTP GET request with a crafted Accept-Language header, arbitrary HTML can be injected into the <html lang=""> tag of the response. This can lead to potential security risks such as cross-site scripting (XSS) attacks.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-8848?
CVE-2025-8848 is classified as a high severity vulnerability due to its potential for HTML injection.
How do I fix CVE-2025-8848?
To fix CVE-2025-8848, update the danny-avila/librechat library to version 0.7.10 or later where the vulnerability is patched.
What kind of attack is associated with CVE-2025-8848?
CVE-2025-8848 is associated with HTML injection attacks via a malicious Accept-Language header.
Who is affected by CVE-2025-8848?
Users of danny-avila/librechat version 0.7.9 are affected by CVE-2025-8848.
What is the potential impact of CVE-2025-8848?
The potential impact of CVE-2025-8848 includes malicious HTML being injected into web responses, which could lead to user data theft or other exploits.