CVE-2025-63639

MEDIUM

Sourcecodester FAQ Bot with AI Assistant v1.0 - XSS

Title source: llm
STIX 2.1

Description

The chat feature in the application Sourcecodester FAQ Bot with AI Assistant v1.0 is vulnerable to Cross-Site Scripting (XSS) due to improper handling of user-supplied input. An attacker can inject malicious HTML or JavaScript into chat messages, which executes in the browser of any user viewing the conversation.

Scores

CVSS v3 6.1
EPSS 0.0004
EPSS Percentile 11.4%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact partial

Details

CWE
CWE-79
Status published
Products (1)
remyandrade/faq_bot_with_ai_assistant 1.0
Published Nov 07, 2025
Tracked Since Feb 18, 2026