Cross-Site Scripting in Deep Chat by Ovidijus Parsiunas
CVE-2026-108852

2.1LOW

Key Information:

Status
Vendor
CVE Published:
11 October 2026

What is CVE-2026-108852?

Deep Chat version 2.5.1 contains a vulnerability that enables attackers to exploit cross-site scripting (XSS) by injecting malicious JavaScript through crafted Markdown links. This occurs because RemarkableConfig.createNew omits proper validation of Remarkable links. Consequently, attackers can manipulate AI-generated responses and addMessage content to execute scripts embedded within the page. Users are at risk when clicking on such links, potentially leading to unauthorized actions within their environment.

Affected Version(s)

Deep Chat 1.4.7 <= 2.5.1

References

CVSS V4

Score:
2.1
Severity:
LOW
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

hieuPenguinnn
.