danny-avila/librechat 0.7.9 contains a stored XSS caused by improper sanitization of the Accept-Language header, letting logged-in users inject arbitrary HTML into the html lang= tag, exploit requires user to be logged in.
id: CVE-2025-8848
info:
name: LibreChat <= 0.7.9 - HTML Injection via Accept-Language Header
au
...