CVE 8.6 HIGH

LibreChat JSON Injection in Chat POST Allows Remote Resource Inclusion and PXSS via Image Upload_CVE-2025-66450

8.6 / 10
HIGH
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:N/SC:L/SI:L/SA:N

Description

LibreChat is a ChatGPT clone with additional features. In versions 0.8.0 and below, when a user posts a question, the iconURL parameter of the POST request can be modified by an attacker. The malicious code is then stored in the chat which can then be shared to other users. When sharing chats with a potentially malicious β€œtracker”, resources loaded can lead to loss of privacy for users who view the chat link that is sent to them. This issue is fixed in version 0.8.1.

AI Analysis

JSON Injection in Chat POST allows remote resource inclusion and PXSS via image upload

Basic Information

ID CVE-2025-66450
Source GitHub_M
Published Dec 11, 2025 at 22:05

Affected Product

Vendor danny-avila
Product LibreChat
Version < 0.8.1
Affected Versions danny-avila LibreChat < 0.8.1

CWE Classification

AI Assessment

AI Score 8.6 / 10
AI Severity High
Vendor danny-avila
Product LibreChat
Version 0.8.0 and below

References

πŸ’­ Join the Security Discussion

πŸ”’ Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.