Unrated severityNVD Advisory· Published Nov 7, 2025· Updated Nov 12, 2025
CVE-2025-63639
CVE-2025-63639
Description
The chat feature in the application Sourcecodester FAQ Bot with AI Assistant v1.0 is vulnerable to Cross-Site Scripting (XSS) due to improper handling of user-supplied input. An attacker can inject malicious HTML or JavaScript into chat messages, which executes in the browser of any user viewing the conversation.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
2(expand)+ 1 more
- (no CPE)
- (no CPE)range: =1.0
Patches
Vulnerability mechanics
References
2News mentions
0No linked articles in our index yet.