Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2025-66452

Опубликовано: 11 дек. 2025
Источник: nvd
CVSS3: 6.1
EPSS Низкий

Описание

LibreChat is a ChatGPT clone with additional features. In versions 0.8.0 and below, there is no handler for JSON parsing errors; SyntaxError from express.json() includes user input in the error message, which gets reflected in responses. User input (including HTML/JavaScript) can be exposed in error responses, creating an XSS risk if Content-Type isn't strictly enforced. This issue does not have a fix at the time of publication.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:librechat:librechat:*:*:*:*:*:*:*:*
Версия до 0.8.0 (включая)

EPSS

Процентиль: 9%
0.00034
Низкий

6.1 Medium

CVSS3

Дефекты

CWE-79

EPSS

Процентиль: 9%
0.00034
Низкий

6.1 Medium

CVSS3

Дефекты

CWE-79