The chat feature in the application Sourcecodester FAQ Bot with AI Assistant v1.0 is vulnerable to Cross-Site Scripting (XSS) due to improper handling of user-supplied input. An attacker can inject malicious HTML or JavaScript into chat messages, which executes in the browser of any user viewing the conversation.
Advisories

No advisories yet.

Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Fri, 07 Nov 2025 20:15:00 +0000

Type Values Removed Values Added
Description The chat feature in the application Sourcecodester FAQ Bot with AI Assistant v1.0 is vulnerable to Cross-Site Scripting (XSS) due to improper handling of user-supplied input. An attacker can inject malicious HTML or JavaScript into chat messages, which executes in the browser of any user viewing the conversation.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2025-11-07T20:05:36.270Z

Reserved: 2025-10-27T00:00:00.000Z

Link: CVE-2025-63639

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2025-11-07T20:15:38.113

Modified: 2025-11-07T20:15:38.113

Link: CVE-2025-63639

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.