CVE-2026-54025: LibreChat is an enhanced ChatGPT clone that supports multiple AI providers. Prior to 0.8.4-rc1, there is a vulnerability in LibreChat's markdown artifact preview pipeline. The marked library v15.0....
Added to the CISA Known Exploited Vulnerabilities catalog on 25 Jun 2026. Vendor: AI/ML. Product: chatgpt. CVSS score: 5.4.
LibreChat is an enhanced ChatGPT clone that supports multiple AI providers. Prior to 0.8.4-rc1, there is a vulnerability in LibreChat's markdown artifact preview pipeline. The marked library v15.0.12 does not HTML-escape double-quote characters in image alt text when a custom renderer falls throu...
Required action: Review and patch if applicable to your AI infrastructure.