Stored Cross-Site Scripting Vulnerability in LibreChat by Danny Avila
CVE-2025-66450
What is CVE-2025-66450?
In LibreChat versions 0.8.0 and earlier, the application is susceptible to a Stored Cross-Site Scripting (XSS) vulnerability. This occurs when an attacker manipulates the iconURL parameter during a POST request, allowing them to inject malicious code. The compromised code can then be stored within the chat's memory, which gets shared with other users. When these recipients open the shared chat, they potentially expose their privacy to unauthorized tracking mechanisms. This vulnerability poses significant privacy risks for users engaged in chat functionalities. To address this issue, users are recommended to upgrade to version 0.8.1 where this vulnerability has been resolved.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
LibreChat < 0.8.1
References
CVSS V4
Timeline
Vulnerability published
Vulnerability Reserved
