Medium severity4.7NVD Advisory· Published Oct 11, 2026
CVE-2026-108852
CVE-2026-108852
Description
Deep Chat through 2.5.1 contains a cross-site scripting vulnerability that allows attackers to inject javascript: links because RemarkableConfig.createNew disables Remarkable link validation. Attackers can place crafted Markdown links in AI responses, addMessage content, or loaded history to execute script in the embedding page when victims click them.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
1Patches
Vulnerability mechanics
References
3- github.com/OvidijusParsiunas/deep-chat/blob/2.5.1/component/src/views/chat/messages/remarkable/remarkableConfig.tsnvd
- hackmd.io/@1ExmmukzRMWN7B4gQ4W-4Q/ovidijusparsiunas-deep-chat-markdown-scheme-validationnvd
- www.vulncheck.com/advisories/deep-chat-through-2.5.1-xss-via-markdown-link-validation-bypassnvd
News mentions
0No linked articles in our index yet.