Skip to content
Noroxi

LibreChat records

52 published records for vendor librechat.

Researcher profile

Entered KEV
0 · 0%
Weaponized
0 · 0%
Pre-auth RCE
1
With a fix record
50%
Median publish → KEV
No record has entered KEV

All records

52 records
  • LibreChat MCP Stdio Remote Command Execution

    CriticalCVSS 9.9No exploitEPSS 4%

    librechat · librechatJan 12, 2026

  • LibreChat through 0.7.4-rc1 does not validate the normalized pathnames of images.

    CriticalCVSS 9.8No exploitEPSS 1%

    librechat · librechatJul 22, 2024

  • LibreChat through 0.7.4-rc1 has incorrect access control for message updates.

    CriticalCVSS 9.8No exploitEPSS 0%

    librechat · librechatJul 22, 2024

  • LibreChat Exfiltrates Server Secrets via MCP Server URL Injection

    CriticalCVSS 9.6No exploitEPSS 0%

    librechat · librechatJun 2, 2026

  • LibreChat: Missing Resource Parameter Validation in MCP OAuth Flow

    CriticalCVSS 9.3No exploitEPSS 0%

    librechat · librechatJun 25, 2026

  • Path Traversal in danny-avila/librechat

    HighCVSS 8.8No exploitEPSS 2%

    librechat · librechatMar 20, 2025

  • Arbitrary File Deletion via Path Traversal in danny-avila/librechat

    CriticalCVSS 9.1No exploitEPSS 1%

    librechat · librechatMar 20, 2025

  • An issue in the upload_documents method of libre-chat v0.0.6 allows attackers to execute a path traversal via supplying a crafted filename i

    CriticalCVSS 9.1No exploitEPSS 1%

    Nov 25, 2024

  • In LibreChat 0.8.1-rc2, a logged-in user obtains a JWT for both the LibreChat API and the RAG API.

    CriticalCVSS 9.0No exploitEPSS 0%

    librechat · librechatMar 18, 2026

  • CVE-2025-8850
    35Monitor

    Insecure API Design in danny-avila/librechat

    HighCVSS 8.8No exploitEPSS 0%

    librechat · librechatOct 30, 2025

  • LibreChat has SSRF protection bypass via IPv4-mapped IPv6 normalization in isPrivateIP

    HighCVSS 8.5No exploitEPSS 0%

    librechat · librechatMar 27, 2026

  • LibreChat is Vulnerable to Server-Side Request Forgery (SSRF) in Actions Capability

    HighCVSS 8.6No exploitEPSS 0%

    librechat · librechatNov 28, 2025

  • LibreChat JSON Injection in Chat POST Allows Remote Resource Inclusion and PXSS via Image Upload

    HighCVSS 8.6No exploitEPSS 0%

    librechat · librechatDec 11, 2025

  • LibreChat is vulnerable to Server-Side Request Forgery due to missing restrictions

    HighCVSS 8.1No exploitEPSS 5%

    librechat · librechatJan 7, 2026

  • LibreChat: 2FA Re-enrollment Allows Full Account 2FA Takeover Without OTP Verification

    HighCVSS 8.1No exploitEPSS 0%

    librechat · librechatJun 25, 2026

  • LibreChat RAG API Authentication Bypass

    HighCVSS 8.0No exploitEPSS 0%

    librechat · librechatMar 18, 2026

  • Unhandled Exception Leading to Server Crash in danny-avila/librechat

    HighCVSS 7.5No exploitEPSS 1%

    librechat · librechatMar 20, 2025

  • Denial of Service in danny-avila/librechat

    HighCVSS 7.5No exploitEPSS 1%

    librechat · librechatMar 20, 2025

  • Improper Input Validation in danny-avila/librechat

    HighCVSS 7.5No exploitEPSS 1%

    librechat · librechatMar 20, 2025

  • CVE-2026-4276
    30Monitor

    LibreChat RAG API, version 0.7.0, contains a log-injection vulnerability that allows attackers to forge log entries.

    HighCVSS 7.5No exploitEPSS 0%

    librechat · librechatMar 16, 2026

  • LibreChat exposes arbitrary chats through Meilisearch engine

    HighCVSS 7.5No exploitEPSS 0%

    librechat · librechatAug 5, 2025

  • LibreChat Server-Side Request Forgery using DNS resolution

    HighCVSS 7.7No exploitEPSS 0%

    librechat · librechatMar 27, 2026

  • CVE-2025-8849
    30Monitor

    Denial of Service in danny-avila/librechat

    HighCVSS 7.5No exploitEPSS 0%

    librechat · librechatOct 30, 2025

  • CVE-2025-7104
    30Monitor

    Mass Assignment in danny-avila/librechat

    HighCVSS 7.5No exploitEPSS 0%

    librechat · librechatSep 29, 2025

  • LibreChat MCP OAuth callback does not validate browser session — allows token theft via redirect link

    HighCVSS 7.6No exploitEPSS 0%

    librechat · librechatMar 13, 2026