Sceawere
Vulnerability Detail
CVE-2026-108852UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Deep Chat XSS via Markdown
Vulnerability Metadata
- Severity
- Medium
- Score / CVSS
- 4.7
- Creation Date
- 3h ago
- Vendor
- OvidijusParsiunas
- Product
- Deep Chat
- Attack Type
- Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
- Vector String
- CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:L/I:L/A:N
- Attack Complexity
- HIGH
Narrative and Response
Description
Deep Chat through 2.5.1 contains a cross-site scripting vulnerability that allows attackers to inject javascript: links because RemarkableConfig.createNew disables Remarkable link validation. Attackers can place crafted Markdown links in AI responses, addMessage content, or loaded history to execute script in the embedding page when victims click them.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "4.7",
"pubDate": "2026-10-11T14:17:04.827Z",
"pubdate": "2026-10-11T14:17:04.827Z",
"executiveSummary": "Deep Chat versions up to 2.5.1 are susceptible to a Cross-Site Scripting (XSS) vulnerability stemming from improper validation of Markdown links within the Remarkable library configuration.\nThe vulnerability allows remote attackers to execute arbitrary JavaScript in the context of the user's session when a victim interacts with a crafted link.\nThis issue affects the rendering component of the Deep Chat interface, specifically where AI-generated responses, message inputs, or message history are processed.\nThe risk is critical, as successful exploitation enables session hijacking, unauthorized actions on behalf of the user, or the exfiltration of sensitive information contained within the browser session.\nExploitation requires no special authentication, as the attack vector is embedded directly into the content processed and rendered by the chat application, requiring only that the victim clicks a malicious link presented in the chat interface.",
"technicalDetails": "The root cause of this vulnerability is a misconfiguration within the Remarkable library implementation used by Deep Chat. Specifically, the function 'RemarkableConfig.createNew' explicitly disables built-in link validation mechanisms that are designed to sanitize user-supplied input.\nBecause standard URL validation is circumvented, the library permits the use of the 'javascript:' URI protocol in Markdown-formatted links. When a user interacts with a rendered Markdown link containing 'javascript:[code]', the browser executes the payload within the context of the web application's origin.\nThe attack flow proceeds as follows: An attacker injects a malicious payload into the application via 'addMessage' content, an AI response, or by manipulating loaded chat history. The payload typically takes the form '[Click Me](javascript:alert(document.cookie))'. Upon rendering the Markdown, the Deep Chat component presents this as a functional, clickable hyperlink.\nWhen an unsuspecting user clicks the link, the browser executes the JavaScript URI, leading to successful XSS execution. This mechanism bypasses standard security expectations for Markdown parsers, which should typically restrict link protocols to safe alternatives like 'http://', 'https://', or 'mailto:'.\nThis vulnerability is present in Deep Chat versions 2.5.1 and earlier. It affects the core component responsible for parsing and rendering dynamic chat content. Because the application processes user and AI-generated messages through the same vulnerable rendering path, the attack surface is broad, covering both historical data and real-time interactions.\nThe post-exploitation impact is limited only by the permissions of the victim's session. An attacker can use the XSS to perform actions that the user is authorized to execute, scrape sensitive data from the DOM, or redirect users to malicious external domains. Given the sensitive nature of chat interfaces, this could lead to the exposure of private conversations or API keys stored in the local session storage."
}