Where
-Infinity
0

LibreChatLibreChat: Incomplete Fix for CVE-2024-11171 — Conversation Import Multer Instance Missing File Size Limits

Risk 38
Severity
6.5
First published (updated )

LibreChatLibreChat: Stored XSS via unescaped image alt text in markdown artifact preview

Risk 34
Severity
5.4
First published (updated )

LibreChatLibreChat: Image Upload Route Bypasses Agent Permission Check — Incomplete Fix for File Upload Authorization

Risk 38
Severity
6.5
First published (updated )

LibreChatLibreChat: SSRF via User-Provided Custom Endpoint baseURL — no private IP validation on user-configured API base URLs

Risk 44
Severity
7.7
First published (updated )

LibreChatLibreChat: 2FA Backup Code Regeneration Without OTP Verification Allows 2FA Bypass

Risk 48
Severity
7.1
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

LibreChatLibreChat: 2FA Re-enrollment Allows Full Account 2FA Takeover Without OTP Verification

Risk 60
Severity
8.1
First published (updated )

LibreChatLibreChat RAG API Authentication Bypass

Risk 73
Severity
8
First published (updated )

LibreChatLibreChat Denial of Service (DoS) via Unhandled Exception in DELETE /api/convos

Risk 27
Severity
6.5
EPSS
0.05%
First published (updated )

librechatLibreChat's Improper Input Validation in Prompt Creation API Enables Unauthorized Permission Changes

Risk 38
Severity
6.5
First published (updated )

danny-avila librechatMass Assignment in Preset Creation Allows User ID Manipulation in danny-avila/librechat

Risk 30
Severity
4.6
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

danny-avila librechatUnhandled Exception in danny-avila/librechat

Risk 38
Severity
6.5
First published (updated )

danny-avila librechatImproper Access Control in danny-avila/LibreChat

Risk 34
Severity
5.4
First published (updated )

danny-avila librechatImproper Input Validation in danny-avila/librechat

Risk 43
Severity
7.5
First published (updated )

danny-avila librechatDenial of Service in danny-avila/librechat

Risk 43
Severity
7.5
First published (updated )

danny-avila librechatUnhandled Exception Leading to Server Crash in danny-avila/librechat

Risk 43
Severity
7.5
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

danny-avila librechatImproper Access Control in danny-avila/librechat

Risk 76
Severity
9.4
First published (updated )

danny-avila librechatIDOR in delete attachments in danny-avila/librechat

Risk 58
Severity
7.6
First published (updated )

danny-avila librechatLogs Debug Injection in danny-avila/librechat

Risk 27
Severity
5.3
First published (updated )

danny-avila librechatArbitrary File Deletion via Path Traversal in danny-avila/librechat

Risk 66
Severity
9.1
First published (updated )

danny-avila librechatPath Traversal in danny-avila/librechat

Risk 79
Severity
8.8
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

librechat librechatLibreChat through 0.7.4-rc1 has incorrect access control for message updates.

Risk 86
Severity
9.8
First published (updated )

librechat librechatPath Traversal

Risk 86
Severity
9.8
First published (updated )

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203