CVE-2026-108852
Received Received - Intake

Cross-Site Scripting in Deep Chat via Malicious Markdown Links

Vulnerability report for CVE-2026-108852, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-11

Last updated on: 2026-10-11

Assigner: VulnCheck

Description

Deep Chat through 2.5.1 contains a cross-site scripting vulnerability that allows attackers to inject javascript: links because RemarkableConfig.createNew disables Remarkable link validation. Attackers can place crafted Markdown links in AI responses, addMessage content, or loaded history to execute script in the embedding page when victims click them.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-11
Last Modified
2026-10-11
Generated
2026-10-11
AI Q&A
2026-10-11
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
OvidijusParsiunas Deep Chat 1.4.7

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-79 The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is a cross-site scripting (XSS) issue in Deep Chat through version 2.5.1. It occurs because RemarkableConfig.createNew disables Remarkable link validation, allowing attackers to inject javascript: links. These crafted Markdown links can be placed in AI responses, messages, or loaded history, executing scripts in the embedding page when clicked by victims.

Detection Guidance

Detecting this XSS vulnerability requires inspecting user-generated content in Deep Chat for crafted Markdown links. Check AI responses, addMessage content, or loaded history for javascript: links or unusual Markdown syntax. Use browser developer tools to monitor for executed scripts when clicking links.

Impact Analysis

If you use Deep Chat through 2.5.1, attackers could trick you into clicking malicious links that execute arbitrary JavaScript in your browser. This could lead to session hijacking, data theft, or unauthorized actions on your behalf while using the application.

Compliance Impact

This vulnerability could potentially violate GDPR and HIPAA compliance by enabling cross-site scripting attacks that may lead to unauthorized data access or manipulation. Attackers could inject malicious scripts via crafted Markdown links, compromising user data or session integrity in applications handling sensitive information.

Mitigation Strategies

Upgrade Deep Chat to a version that validates Remarkable links. Implement input validation to block javascript: links in Markdown. Use Content Security Policy (CSP) headers to restrict script execution. Sanitize AI responses and user messages before rendering.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-108852. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart