Cross-Site Scripting in Deep Chat by Ovidijus Parsiunas
CVE-2026-108852
2.1LOW
What is CVE-2026-108852?
Deep Chat version 2.5.1 contains a vulnerability that enables attackers to exploit cross-site scripting (XSS) by injecting malicious JavaScript through crafted Markdown links. This occurs because RemarkableConfig.createNew omits proper validation of Remarkable links. Consequently, attackers can manipulate AI-generated responses and addMessage content to execute scripts embedded within the page. Users are at risk when clicking on such links, potentially leading to unauthorized actions within their environment.
Affected Version(s)
Deep Chat 1.4.7 <= 2.5.1
