Executive brief
LibreChat, an open-source interface for AI models like ChatGPT, contains a security flaw in how it previews shared documents. An attacker can create a specially crafted conversation that, when shared and viewed by another user, automatically redirects the victim's browser to a malicious website. This could be used for phishing or to trick users into visiting dangerous pages while their session is active.
Technical details
A stored Cross-Site Scripting (XSS) vulnerability exists in LibreChat's markdown artifact preview pipeline due to improper escaping in the 'marked' library (v15.0.12). When the 'generateMarkdownHtml' function in 'client/src/utils/markdown.ts' uses a custom image renderer that falls back to the default renderer for safe URLs, the default renderer fails to HTML-escape double-quote characters in the image 'alt' text. An authenticated attacker can import a crafted conversation JSON containing a malicious markdown artifact and generate a public share link. When a victim views the shared link, the unescaped 'alt' text breaks out of the attribute to inject an 'onload' event handler, executing arbitrary JavaScript within the Sandpack preview iframe. This can be used to perform a top-level window redirection since LibreChat lacks restrictive Content-Security-Policy (CSP) or X-Frame-Options headers. The issue is fixed in version 0.8.4-rc1.
Affected products
- danny-avila LibreChat < 0.8.4-rc1
Timeline
- 2026-06-02: advisory: GitHub Security Advisory published
- 2026-06-25: disclosed: NVD publication date