VYPR
Unrated severityNVD Advisory· Published Jan 30, 2025· Updated Feb 18, 2025

Stored Cross-Site vulnerability in EmbedAI

CVE-2025-0747

Description

A Stored Cross-Site Scripting vulnerability has been found in EmbedAI. This vulnerability allows an authenticated attacker to inject a malicious JavaScript code into a message that will be executed when a user opens the chat.

Affected products

2
  • EmbedAI/EmbedAIllm-create2 versions
    (expand)+ 1 more
    • (no CPE)
    • (no CPE)range: 0

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.