CVE-2025-41258: LibreChat RAG API Authentication Bypass
LibreChat version 0.8.1-rc2 uses the same JWT secret for the user session mechanism and RAG API which compromises the service-level authentication of the RAG API.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-41258?
CVE-2025-41258 is a high severity vulnerability due to its potential for authentication bypass.
How does CVE-2025-41258 affect LibreChat?
CVE-2025-41258 affects LibreChat by allowing unauthorized access to the RAG API, compromising the authentication process.
How do I fix CVE-2025-41258?
To fix CVE-2025-41258, you should update to a patched version of LibreChat that uses a unique JWT secret for the user session and RAG API.
Is there a workaround for CVE-2025-41258?
A temporary workaround for CVE-2025-41258 includes implementing additional access controls on the RAG API until an official patch is released.
What versions of LibreChat are affected by CVE-2025-41258?
CVE-2025-41258 affects LibreChat version 0.8.1-rc2 and potentially other versions that utilize the same JWT secret for authentication.