Cross-site scripting in LibreChat - #VU133253
Published: June 3, 2026
LibreChat
Detailed vulnerability description
The vulnerability allows a remote user to execute arbitrary script in the victim's browser.
The vulnerability exists due to cross-site scripting in the markdown artifact preview pipeline when rendering crafted markdown image alt text. A remote user can import a crafted conversation and share a public link to execute arbitrary script in the victim's browser.
User interaction is required to open the shared conversation link.