CVE-2025-66201: LibreChat is Vulnerable to Server-Side Request Forgery (SSRF) in Actions Capability
LibreChat is a ChatGPT clone with additional features. Prior to version 0.8.1-rc2, LibreChat is vulnerable to Server-side Request Forgery (SSRF), by passing specially crafted OpenAPI specs to its "Actions" feature and making the LLM use those actions. It could be used by an authenticated user with access to this feature to access URLs only accessible to the LibreChat server (such as cloud metadata services, through which impersonation of the server might be possible). This issue has been patched in version 0.8.1-rc2.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-66201?
CVE-2025-66201 has a moderate severity level due to the potential for Server-side Request Forgery (SSRF), which could allow attackers to access internal resources.
How do I fix CVE-2025-66201?
To fix CVE-2025-66201, upgrade LibreChat to version 0.8.1-rc2 or later, which addresses the underlying vulnerability.
What are the risks associated with CVE-2025-66201?
The risks associated with CVE-2025-66201 include unauthorized access to internal systems and data potentially leading to information leakage.
Who is affected by CVE-2025-66201?
CVE-2025-66201 affects all versions of LibreChat prior to 0.8.1-rc2.
What is the nature of the vulnerability in CVE-2025-66201?
CVE-2025-66201 involves Server-side Request Forgery (SSRF) enabled by passing malicious OpenAPI specifications to the Actions feature.