https://seclists.org/oss-sec/2026/q1/335: [SBA-ADV-20251205-01] LibChat 0.8.1-rc2 RAG API Authentication Bypass
Published Mar 18, 2026
·Updated
Affected Software
1 affected component
librechat librechat
The severity of SBA-ADV-20251205-01 is classified as critical due to the potential for unauthorized access to sensitive data.
To fix SBA-ADV-20251205-01, upgrade to LibreChat version 0.8.1-rc3 or later where the authentication bypass issue has been addressed.
SBA-ADV-20251205-01 affects LibreChat version 0.8.1-rc2 and prior versions.
Exploitation of SBA-ADV-20251205-01 can involve bypassing JWT authentication to gain unauthorized API access.
Temporary workarounds for SBA-ADV-20251205-01 include disabling the RAG API until the upgrade is performed.