Cross-site scripting in LibreChat - CVE-2026-54025
Published: June 3, 2026
Vulnerability details
The vulnerability allows a remote user to execute arbitrary script in the victim's browser.
The vulnerability exists due to cross-site scripting in the markdown artifact preview pipeline when rendering crafted markdown image alt text. A remote user can import a crafted conversation and share a public link to execute arbitrary script in the victim's browser.
User interaction is required to open the shared conversation link.