目标: 1000 元 · 已筹: 1336 元
danny-avila/librechat 0.7.9 contains a stored XSS caused by improper sanitization of the Accept-Language header, letting logged-in users inject arbitrary HTML into the html lang= tag, exploit requires user to be logged in.
登录后查看神龙缓存的 POC 文件快照