CVE-2025-66452 | danny-avila LibreChat up to 0.8.1 JSON Parser express.json cross site scripting
A vulnerability was found in danny-avila LibreChat up to 0.8.1 and classified as problematic. Affected by this issue is the function express.json of the component JSON Parser. The manipulation results in cross site scripting.
This vulnerability was named CVE-2025-66452. The attack may be performed from remote. There is no available exploit.