CVE-2024-10359: Mass Assignment in Preset Creation Allows User ID Manipulation in danny-avila/librechat

Published Mar 20, 2025
·
Updated

In danny-avila/librechat version v0.7.5-rc2, a vulnerability exists in the preset creation functionality where a user can manipulate the user ID field through mass assignment. This allows an attacker to inject a different user ID into the preset object, causing the preset to appear in the UI of another user. The vulnerability arises because the backend saves the entire object received without validating the attributes and their values, impacting both integrity and confidentiality.

Affected Software

2 affected components
danny-avila librechat
librechat librechat=0.7.5-rc2

Event History

Mar 20, 2025
CVE Published
via MITRE·10:10 AM
Data Sourced
via MITRE·10:10 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·10:15 AM
RemedyDescriptionSeverityWeaknessAffected Software
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2024-10359?

CVE-2024-10359 is categorized as a medium severity vulnerability due to its potential to manipulate user IDs.

2

How do I fix CVE-2024-10359?

To fix CVE-2024-10359, it is recommended to update to the latest version of librechat that addresses this issue.

3

What specific functionality is affected by CVE-2024-10359?

CVE-2024-10359 affects the preset creation functionality, allowing user ID manipulation through mass assignment.

4

What can an attacker achieve through CVE-2024-10359?

An attacker can inject a different user ID into the preset object, leading to unauthorized access or actions.

5

Which version of librechat is affected by CVE-2024-10359?

CVE-2024-10359 affects librechat version v0.7.5-rc2.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203