Intel

AIKIDO-2024-10133

librechat-data-provider is vulnerable to Cross-site Scripting

Cross-site Scripting Pre-CVE
Found by Aikido Intel before public disclosure or CVE publication.
Published Jun 21, 2024

50

Medium Risk

This Affects:

JSlibrechat-data-provider
0.1.0 - 0.6.8
Fixed in 0.6.9
Are you affected? Scan for Free

TL;DR

Affected versions of the librechat-data-provider package are vulnerable to multiple Cross-site Scripting (XSS) vulnerabilities.

Who does this affect?

You are affected if you use a vulnerable version of librechat-data-provider.

Background info

librechat-data-provider is vulnerable to Cross-site Scripting in versions 0.1.0 - 0.6.8.

How to fix this

Upgrade librechat-data-provider to a patch version.