Exploitation Summary
EIP tracks 1 public exploit for CVE-2025-51858. PoCs published by Secsys-FDU.
AI-analyzed exploit summary Technical analysis of CVE-2025-51858 detailing a self-XSS vulnerability in ChatPlayground.ai's chat component and an IDOR in the /api/chat-history endpoint, enabling JWT token theft and persistent data leakage.
Description
Self Cross-Site Scripting (XSS) vulnerability in ChatPlayground.ai through 2025-05-24, allows attackers to execute arbitrary code and gain sensitive information via a crafted SVG file contents sent through the chat component.
Exploits (1)
Technical analysis of CVE-2025-51858 detailing a self-XSS vulnerability in ChatPlayground.ai's chat component and an IDOR in the /api/chat-history endpoint, enabling JWT token theft and persistent data leakage.
References (1)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N