Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

LibreChat — Vulnerabilities & Security Advisories 31

All 31 CVE vulnerabilities found in LibreChat, with AI-generated Chinese analysis, references, and POCs.

This page documents security vulnerabilities associated with the LibreChat software product, specifically focusing on weaknesses in its architecture and implementation. It aggregates a comprehensive collection of reported issues, including cross-site scripting, authentication bypasses, and insecure direct object references, covering data from major public vulnerability databases and vendor advisories between January 2023 and the present date. By organizing these records chronologically and by severity, the page allows users to track LibreChat’s security posture over time, analyze recurring patterns in specific weakness classes, and review the historical remediation efforts for the platform. This resource is designed to assist security researchers, system administrators, and developers in understanding the risk landscape surrounding this specific open-source chat interface. Rather than providing a simple list of flaws, it offers contextual information about how these vulnerabilities were discovered, their potential impact on deployment environments, and the patches released to address them. Users can search for specific weakness identifiers or browse by severity ratings to identify which issues may affect their own instances. The content is derived from authoritative sources, ensuring accuracy and relevance for those conducting threat modeling or compliance audits. This aggregation serves as a centralized reference point for assessing the ongoing security health of LibreChat deployments, enabling informed decisions regarding upgrades and mitigation strategies without requiring manual cross-referencing of multiple external feeds.

Vendor: danny-avila

CVE IDTitleCVSSSeverityPublished
CVE-2026-54024 LibreChat: Incomplete Fix for CVE-2024-11171 — Conversation Import Multer Instance Missing File Size Limits CWE-770 6.5 Medium2026-06-25
CVE-2026-54025 LibreChat: Stored XSS via unescaped image alt text in markdown artifact preview CWE-79 5.4 Medium2026-06-25
CVE-2026-54027 LibreChat: Image Upload Route Bypasses Agent Permission Check — Incomplete Fix for File Upload Authorization CWE-862 6.5 Medium2026-06-25
CVE-2026-54029 LibreChat: IDOR in Message Deletion — Incomplete Fix for CVE-2024-41703 Leaves deleteMessages() Without User Filter CWE-862 5.3 Medium2026-06-25
CVE-2026-54033 LibreChat: SSRF via User-Provided Custom Endpoint baseURL — no private IP validation on user-configured API base URLs CWE-918 7.7 High2026-06-25
CVE-2026-54037 LibreChat: Incomplete Fix for CVE-2025-7105 — /api/convos/duplicate Lacks Rate Limiting Applied to /api/convos/fork CWE-770 6.5 Medium2026-06-25
CVE-2026-54030 LibreChat: Missing Resource Parameter Validation in MCP OAuth Flow CWE-346 8.0 High2026-06-25
CVE-2026-54040 LibreChat: 2FA Backup Code Regeneration Without OTP Verification Allows 2FA Bypass CWE-306 5.9 Medium2026-06-25
CVE-2026-54036 LibreChat: 2FA Re-enrollment Allows Full Account 2FA Takeover Without OTP Verification CWE-306 5.3 Medium2026-06-25
CVE-2026-44654 LibreChat: Shared-agent editor can globally delete owner's file records — breaks owner's other private agents CWE-863--2026-06-02
CVE-2026-44653 LibreChat Shared MCP Server View Leaks Decrypted Admin Secrets CWE-201 6.5 Medium2026-06-02
CVE-2026-32625 LibreChat Exfiltrates Server Secrets via MCP Server URL Injection CWE-200 9.6 Critical2026-06-02
CVE-2026-31942 LibreChat has IDOR in API Keys Management that allows any authenticated user to overwrite other users' API keys CWE-862 7.1 High2026-06-02
CVE-2026-34371 LibreChat Affected by Arbitrary File Write via `execute_code` Artifact Filename Traversal CWE-22 6.3 Medium2026-04-07
CVE-2026-31951 LibreChat's MCP Server Header Injection Enables OAuth Token Theft CWE-200 6.8 Medium2026-03-27
CVE-2026-31950 LibreChat's IDOR in SSE Stream Subscription Allows Reading Other Users' Chats CWE-284 5.3 Medium2026-03-27
CVE-2026-31945 LibreChat Server-Side Request Forgery using DNS resolution CWE-918 7.7 High2026-03-27
CVE-2026-31943 LibreChat has SSRF protection bypass via IPv4-mapped IPv6 normalization in isPrivateIP CWE-918 8.5 High2026-03-27
CVE-2026-33265 LibreChat 安全漏洞 CWE-669 6.3 Medium2026-03-18
CVE-2025-41258 LibreChat RAG API Authentication Bypass CWE-284 8.0 High2026-03-18
CVE-2026-31949 LibreChat Denial of Service (DoS) via Unhandled Exception in DELETE /api/convos CWE-248 6.5 Medium2026-03-13
CVE-2026-31944 LibreChat MCP OAuth callback does not validate browser session — allows token theft via redirect link CWE-306 7.6 High2026-03-13
CVE-2026-22252 LibreChat MCP Stdio Remote Command Execution CWE-285 9.1 Critical2026-01-12
CVE-2025-69222 LibreChat is vulnerable to Server-Side Request Forgery due to missing restrictions CWE-918 9.1 Critical2026-01-07
CVE-2025-69221 LibreChat has Insufficient Access Control for Agent Permission Queries CWE-862 4.3 Medium2026-01-07
CVE-2025-69220 LibreChat has Insufficient Access Control for Agent Files CWE-862 7.1 High2026-01-07
CVE-2025-66452 LibreChat's lack of JSON parsing error handling can lead to XSS CWE-79 6.1AIMediumAI2025-12-11
CVE-2025-66451 LibreChat's Improper Input Validation in Prompt Creation API Enables Unauthorized Permission Changes CWE-20 4.3AIMediumAI2025-12-11
CVE-2025-66450 LibreChat JSON Injection in Chat POST Allows Remote Resource Inclusion and PXSS via Image Upload CWE-80 6.3AIMediumAI2025-12-11
CVE-2025-66201 LibreChat is Vulnerable to Server-Side Request Forgery (SSRF) in Actions Capability CWE-20 8.1 -2025-11-29

All 31 known CVE vulnerabilities affecting LibreChat with full Chinese analysis, references, and POCs where available.