librechat - Config Exposure
Detected the `/api/config` endpoint of the LibreChat web application was publicly accessible, potentially exposing internal configuration details.
LibreChatPoC 已收录
CVSS—
暂无产品描述。
共找到 2 条公开漏洞记录
Detected the `/api/config` endpoint of the LibreChat web application was publicly accessible, potentially exposing internal configuration details.
A vulnerability in danny-avila/librechat version 0.7.9 allows for HTML injection via the Accept-Language header. When a logged-in user sends an HTTP GET request with a crafted Accept-Language header, arbitrary HTML can be injected into the <html lang=""> tag of the response. This can lead to potential security risks such as cross-site scripting (XSS) attacks.