CVE-2026-22252: LibreChat MCP Stdio Remote Command Execution
LibreChat is a ChatGPT clone with additional features. Prior to v0.8.2-rc2, LibreChat's MCP stdio transport accepts arbitrary commands without validation, allowing any authenticated user to execute shell commands as root inside the container through a single API request. This vulnerability is fixed in v0.8.2-rc2.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2026-22252?
CVE-2026-22252 is considered a critical vulnerability due to its potential for remote command execution as root.
How do I fix CVE-2026-22252?
To fix CVE-2026-22252, upgrade LibreChat to version 0.8.2-rc2 or later, which includes the necessary security patches.
Who is affected by CVE-2026-22252?
Any user running LibreChat versions prior to 0.8.2-rc2 is at risk of CVE-2026-22252.
What type of vulnerability is CVE-2026-22252?
CVE-2026-22252 is a remote command execution vulnerability affecting LibreChat.
Can unauthenticated users exploit CVE-2026-22252?
No, only authenticated users can exploit CVE-2026-22252 to execute arbitrary commands.