CVE-2025-51864
MEDIUMAIBOX LLM chat <2025-05-27 - XSS
Title source: llmDescription
A reflected cross-site scripting (XSS) vulnerability exists in AIBOX LLM chat (chat.aibox365.cn) through 2025-05-27, allowing attackers to hijack accounts through stolen JWT tokens.
Exploits (1)
Scores
CVSS v3
6.5
EPSS
0.0005
EPSS Percentile
16.9%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
CISA SSVC
Vulnrichment
Exploitation
poc
Automatable
no
Technical Impact
partial
Details
CWE
CWE-79
Status
published
Published
Jul 22, 2025
Tracked Since
Feb 18, 2026