CVE-2025-69221: LibreChat has Insufficient Access Control for Agent Permission Queries

Published Jan 7, 2026
·
Updated

LibreChat is a ChatGPT clone with additional features. Version 0.8.1-rc2 does not enforce proper access control when querying agent permissions. An authenticated attacker can read the permissions of arbitrary agents, even if they have no permissions for this agent. LibreChat allows the configuration of agents that have a predefined set of instructions and context. Private agents are not visible to other users. However, if an attacker knows the agent ID, they can read the permissions of the agent including the permissions individually assigned to other users. This issue is fixed in version 0.8.2-rc2.

Affected Software

3 affected components
librechat librechat<0.8.2-rc2
librechat librechat=0.8.1
librechat librechat=0.8.1-rc1

Event History

Jan 7, 2026
CVE Published
via MITRE·09:01 PM
Data Sourced
via MITRE·09:01 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·09:15 PM
RemedyDescriptionSeverityWeaknessAffected Software
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2025-69221?

CVE-2025-69221 has a moderate severity level due to improper access control allowing authenticated attackers to access agent permissions.

2

How do I fix CVE-2025-69221?

To fix CVE-2025-69221, update LibreChat to version 0.8.2-rc2 or later where the access control vulnerability has been addressed.

3

Who is affected by CVE-2025-69221?

CVE-2025-69221 affects users of LibreChat version 0.8.1-rc2 and earlier.

4

What type of vulnerability is CVE-2025-69221?

CVE-2025-69221 is an access control vulnerability that allows authenticated users to read permissions of arbitrary agents.

5

Can the CVE-2025-69221 vulnerability be exploited remotely?

No, CVE-2025-69221 requires authentication, so only authenticated users with access can exploit the vulnerability.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203