{ "dataType": "CVE_RECORD", "dataVersion": "5.2", "cveMetadata": { "cveId": "CVE-2026-108852", "assignerOrgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10", "state": "PUBLISHED", "assignerShortName": "VulnCheck", "dateReserved": "2026-10-11T12:57:38.031Z", "datePublished": "2026-10-11T13:26:02.055Z", "dateUpdated": "2026-10-11T13:26:02.055Z" }, "containers": { "cna": { "providerMetadata": { "orgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10", "shortName": "VulnCheck", "dateUpdated": "2026-10-11T13:26:02.055Z" }, "datePublic": "2026-10-11T00:00:00.000Z", "title": "Deep Chat through 2.5.1 XSS via Markdown Link Validation Bypass", "descriptions": [ { "lang": "en", "value": "Deep Chat through 2.5.1 contains a cross-site scripting vulnerability that allows attackers to inject javascript: links because RemarkableConfig.createNew disables Remarkable link validation. Attackers can place crafted Markdown links in AI responses, addMessage content, or loaded history to execute script in the embedding page when victims click them." } ], "problemTypes": [ { "descriptions": [ { "lang": "en", "description": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')", "cweId": "CWE-79", "type": "CWE" } ] } ], "affected": [ { "vendor": "OvidijusParsiunas", "product": "Deep Chat", "defaultStatus": "unaffected", "versions": [ { "version": "1.4.7", "lessThanOrEqual": "2.5.1", "status": "affected", "versionType": "semver" } ], "packageURL": "pkg:npm/deep-chat", "repo": "https://github.com/OvidijusParsiunas/deep-chat" } ], "cpeApplicability": [ { "nodes": [ { "operator": "OR", "negate": false, "cpeMatch": [ { "vulnerable": true, "criteria": "cpe:2.3:a:thinkinai:deepchat:*:*:*:*:*:*:*:*", "versionStartIncluding": "1.4.7", "versionEndIncluding": "2.5.1" } ] } ] } ], "metrics": [ { "format": "CVSS", "cvssV4_0": { "version": "4.0", "vectorString": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N", "attackVector": "NETWORK", "attackComplexity": "LOW", "attackRequirements": "PRESENT", "privilegesRequired": "NONE", "userInteraction": "ACTIVE", "vulnConfidentialityImpact": "NONE", "vulnIntegrityImpact": "NONE", "vulnAvailabilityImpact": "NONE", "subConfidentialityImpact": "LOW", "subIntegrityImpact": "LOW", "subAvailabilityImpact": "NONE", "baseScore": 2.1, "baseSeverity": "LOW" } }, { "format": "CVSS", "cvssV3_1": { "version": "3.1", "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:L/I:L/A:N", "attackVector": "NETWORK", "attackComplexity": "HIGH", "privilegesRequired": "NONE", "userInteraction": "REQUIRED", "scope": "CHANGED", "confidentialityImpact": "LOW", "integrityImpact": "LOW", "availabilityImpact": "NONE", "baseScore": 4.7, "baseSeverity": "MEDIUM" } } ], "references": [ { "url": "https://hackmd.io/@1ExmmukzRMWN7B4gQ4W-4Q/ovidijusparsiunas-deep-chat-markdown-scheme-validation", "tags": [ "third-party-advisory" ] }, { "url": "https://github.com/OvidijusParsiunas/deep-chat/blob/2.5.1/component/src/views/chat/messages/remarkable/remarkableConfig.ts#L74-L78", "tags": [ "technical-description" ] }, { "url": "https://github.com/OvidijusParsiunas/deep-chat", "tags": [ "product" ] }, { "name": "VulnCheck Advisory: Deep Chat through 2.5.1 XSS via Markdown Link Validation Bypass", "tags": [ "third-party-advisory" ], "url": "https://www.vulncheck.com/advisories/deep-chat-through-2.5.1-xss-via-markdown-link-validation-bypass" } ], "credits": [ { "lang": "en", "value": "hieuPenguinnn", "type": "finder" } ], "x_generator": { "engine": "vulncheck-endgame" } } } }