Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CVE-2024-10359— Mass Assignment in Preset Creation Allows User ID Manipulation in danny-avila/librechat

EPSS 0.20% · P41
Get alerts for future matching vulnerabilitiesLog in to subscribe

I. Basic Information for CVE-2024-10359

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Mass Assignment in Preset Creation Allows User ID Manipulation in danny-avila/librechat
Source: NVD (National Vulnerability Database)
Vulnerability Description
In danny-avila/librechat version v0.7.5-rc2, a vulnerability exists in the preset creation functionality where a user can manipulate the user ID field through mass assignment. This allows an attacker to inject a different user ID into the preset object, causing the preset to appear in the UI of another user. The vulnerability arises because the backend saves the entire object received without validating the attributes and their values, impacting both integrity and confidentiality.
Source: NVD (National Vulnerability Database)
CVSS Information
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Type
CWE-915
Source: NVD (National Vulnerability Database)
Vulnerability Title
LibreChat 安全漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
LibreChat是Danny Avila个人开发者的一个增强的 ChatGPT 克隆。 LibreChat v0.7.5-rc2版本存在安全漏洞,该漏洞源于预设创建功能允许用户操纵用户ID字段,可能导致预设出现在其他用户界面。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

VendorProductAffected VersionsCPESubscribe
danny-aviladanny-avila/librechat unspecified ~ 0.7.5 -

II. Public POCs for CVE-2024-10359

#POC DescriptionSource LinkShenlong Link
AI-Generated POCPremium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2024-10359

登录查看更多情报信息。

Same Patch Batch · danny-avila · 2025-03-20 · 11 CVEs total

CVE-2024-12580Logs Debug Injection in danny-avila/librechat
CVE-2024-11173Unhandled Exception in danny-avila/librechat
CVE-2024-11169Unhandled Exception Leading to Server Crash in danny-avila/librechat
CVE-2024-11170Path Traversal in danny-avila/librechat
CVE-2024-11172Denial of Service in danny-avila/librechat
CVE-2024-11171Improper Input Validation in danny-avila/librechat
CVE-2024-11167Improper Access Control in danny-avila/librechat
CVE-2024-10366IDOR in delete attachments in danny-avila/librechat
CVE-2024-10363Improper Access Control in danny-avila/LibreChat
CVE-2024-10361Arbitrary File Deletion via Path Traversal in danny-avila/librechat

IV. Related Vulnerabilities

V. Comments for CVE-2024-10359

No comments yet


Leave a comment