Medium severity6.1NVD Advisory· Published Nov 7, 2025· Updated Jun 17, 2026
CVE-2025-63639
CVE-2025-63639
Description
The chat feature in the application Sourcecodester FAQ Bot with AI Assistant v1.0 is vulnerable to Cross-Site Scripting (XSS) due to improper handling of user-supplied input. An attacker can inject malicious HTML or JavaScript into chat messages, which executes in the browser of any user viewing the conversation.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3- cpe:2.3:a:remyandrade:faq_bot_with_ai_assistant:1.0:*:*:*:*:*:*:*
1.0+ 1 more
- (no CPE)range: 1.0
- (no CPE)
Patches
Vulnerability mechanics
References
2- github.com/ChuckBartowski7/Vulnerability-Research/blob/main/CVE-2025-63639/README.mdnvdExploitMitigationThird Party Advisory
- www.sourcecodester.com/javascript/18413/faq-bot-ai-assistant-using-html-css-and-javascript-source-code.htmlnvdProduct
News mentions
0No linked articles in our index yet.