← Späť na vyhľadávanie CVE

CVE-2026-54025

LibreChat

Popis

LibreChat is an enhanced ChatGPT clone that supports multiple AI providers. Prior to 0.8.4-rc1, there is a vulnerability in LibreChat-s markdown artifact preview pipeline. The marked library v15.0.12 does not HTML-escape double-quote characters in image alt text when a custom renderer falls through to the default renderer. LibreChat-s generateMarkdownHtml function (in client/src/utils/markdown.ts) installs a custom image renderer that returns false for URLs passing the isSafeUrl allowlist check, which causes marked to fall back to its built-in renderer. That built-in renderer inserts the raw alt text into the alt=-...- attribute without escaping double-quote characters. An attacker can craft an alt text such as - onload=-payload to break out of the attribute and inject an arbitrary event handler. The resulting HTML is then assigned to document.getElementById(-content-).innerHTML inside the Sandpack preview iframe, causing the payload to execute in the victim-s browser. This vulnerability is fixed in 0.8.4-rc1.

CVSS 5.4EPSS 0.16199999999999998%Riziko 0.55
Zobraziť zdroj
Zverejnené
2026-06-25 17:16:40
Dotknuté verzie
<0.8.4-rc1
Typ
Webová aplikácia
Vektor
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N