MIRAGE
Threat IntelligenceCVEs › CVE-2025-8848

CVE-2025-8848 — exposed on the internet

CVE-2025-8848: CWE-94 Improper Control of Generation of Code in danny-avila danny-avila/librechat

Internet exposure observed by OffSeq scans · last 30 days

3
Exposed hosts
4.8
CVSS
0.4%
EPSS

Found on 3 internet-exposed hosts by OffSeq scans; no in-the-wild exploitation has been observed against OffSeq honeypots in this window.

About CVE-2025-8848

A vulnerability in danny-avila/librechat version 0.7.9 allows for HTML injection via the Accept-Language header. When a logged-in user sends an HTTP GET request with a crafted Accept-Language header, arbitrary HTML can be injected into the <html lang=""> tag of the response. This can lead to potential security risks such as cross-site scripting (XSS) attacks.

Vendor: danny-avilaCWE-94

OffSeq internet scanning found CVE-2025-8848 on 3 exposed hosts in the last 30 days. OffSeq honeypots have not recorded in-the-wild exploitation of this CVE in the current window — this page tracks its exposure footprint and status; if exploitation begins, the live honeypot signal will appear here.

Exposed-host countries

Exposed via

http

Open the live CVE-2025-8848 view →

References