PatchSiren cyber security CVE debrief
CVE-2026-108852 OvidijusParsiunas CVE debrief
Deep Chat versions up to 2.5.1 contain a cross-site scripting vulnerability due to a Markdown link validation bypass. This allows attackers to inject JavaScript links, potentially leading to script execution when victims click on crafted links in AI responses, chat messages, or loaded history. The vulnerability is caused by RemarkableConfig.createNew disabling Remarkable link validation, allowing for crafted Markdown links to be used for XSS attacks. Defenders should prioritize verifying and updating Deep Chat installations to prevent potential script injection attacks.
- Vendor
- OvidijusParsiunas
- Product
- Deep Chat
- CVSS
- LOW 2.1
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-10-11
- Original CVE updated
- 2026-10-11
- Advisory published
- 2026-10-11
- Advisory updated
- 2026-10-11
Who should care
Defenders responsible for Deep Chat installations should assess exposure and prioritize updates to prevent potential script injection attacks. Security teams should monitor chat messages and AI responses for potential XSS attempts and implement additional security measures to prevent attacks. Operators and administrators of Deep Chat should review and verify installations to ensure they are up-to-date and secure.
Why it matters
CVE-2026-108852 is a cross-site scripting vulnerability in Deep Chat versions up to 2.5.1. Defenders should prioritize verifying and updating installations to prevent potential script injection attacks. The vulnerability allows attackers to inject JavaScript links via crafted Markdown links in AI responses, chat messages, or loaded history.
- Defenders must verify Deep Chat installations to prevent potential script injection attacks.
- Security teams should monitor chat messages and AI responses for potential XSS attempts.
- Updating Deep Chat to a fixed version is crucial to prevent exploitation.
- Remediation priority is high for deployments with untrusted user input.
Technical summary
The vulnerability is caused by RemarkableConfig.createNew disabling Remarkable link validation, allowing for crafted Markdown links to be used for XSS attacks. Attackers can place these links in AI responses, chat messages, or loaded history to execute script in the embedding page when victims click them. This allows for potential script injection attacks, highlighting the need for defenders to prioritize verifying and updating Deep Chat installations. The vulnerability affects Deep Chat versions up to 2.5.1 and requires immediate attention to prevent exploitation.
Defensive priority
Defenders should prioritize verifying and updating Deep Chat installations to prevent potential script injection attacks.
Recommended defensive actions
- Verify Deep Chat installations for version 2.5.1 or earlier
- Update Deep Chat to a version that fixes the Markdown link validation bypass
- Monitor chat messages and AI responses for potential script injection attempts
- Implement additional security measures to prevent XSS attacks
- Review compensating controls for exposed systems while remediation is scheduled and verified
- Check relevant monitoring, detection, and logs for exposed assets that need extra review
- Track exceptions, retest remediated assets, and close the item only after evidence is documented
Evidence notes
The vulnerability is caused by RemarkableConfig.createNew disabling Remarkable link validation, allowing for crafted Markdown links to be used for XSS attacks. Attackers can place these links in AI responses, chat messages, or loaded history to execute script in the embedding page when victims click them. Evidence is limited to public sources and CVE Program records. Defenders should verify Deep Chat installations and monitor chat messages and AI responses for potential XSS attempts.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-108852 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-108852
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-108852 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-108852
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Deep Chat through 2.5.1 XSS via Markdown Link Validation Bypass
Unverified legacy reference
URL: https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2026/108xxx/CVE-2026-108852.json
cve_program_cvelist_v5
-
Source reference
Unverified legacy reference
URL: https://hackmd.io/@1ExmmukzRMWN7B4gQ4W-4Q/ovidijusparsiunas-deep-chat-markdown-scheme-validation
Supplemental source - third-party-advisory
-
Source reference
Unverified legacy reference
URL: https://github.com/OvidijusParsiunas/deep-chat/blob/2.5.1/component/src/views/chat/messages/remarkable/remarkableConfig.ts
Supplemental source - technical-description
-
Source reference
Unverified legacy reference
URL: https://github.com/OvidijusParsiunas/deep-chat
Supplemental source - product
-
Source reference
Unverified legacy reference
URL: https://www.vulncheck.com/advisories/deep-chat-through-2.5.1-xss-via-markdown-link-validation-bypass
Supplemental source - third-party-advisory
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.