AUGUST 4, 2026
Live Feed
Back to database
Case File

CVE-2025-8848

MEDIUM · CVSS 5.4 EPSS 0.42%

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2025-10-22 · Last synced 2026-08-04

CyberRota Analysis

This is a medium severity vulnerability with a CVSS score of 5.4. See the original NVD description below for full technical details.

CVE
CVE-2025-8848
Severity
MEDIUM
CVSS
5.4
EPSS
0.42%

Original NVD Description

A vulnerability in danny-avila/librechat version 0.7.9 allows for HTML injection via the Accept-Language header. When a logged-in user sends an HTTP GET request with a crafted Accept-Language header, arbitrary HTML can be injected into the <html lang=""> tag of the response. This can lead to potential security risks such as cross-site scripting (XSS) attacks.

Related CVEs

Other vulnerabilities affecting the same vendor(s)