Where
-Infinity
0

Vendor Risk Score

See how librechat compares to other vendors in security performance

View Risk Score →

LibreChatLibreChat: Incomplete Fix for CVE-2024-11171 — Conversation Import Multer Instance Missing File Size Limits

Risk 38
Severity
6.5
First published (updated )

LibreChatLibreChat: Stored XSS via unescaped image alt text in markdown artifact preview

Risk 34
Severity
5.4
First published (updated )

LibreChatLibreChat: Image Upload Route Bypasses Agent Permission Check — Incomplete Fix for File Upload Authorization

Risk 38
Severity
6.5
First published (updated )

librechat librechatLibreChat: IDOR in Message Deletion — Incomplete Fix for CVE-2024-41703 Leaves deleteMessages() Without User Filter

Risk 38
Severity
6.5
First published (updated )

LibreChatLibreChat: SSRF via User-Provided Custom Endpoint baseURL — no private IP validation on user-configured API base URLs

Risk 44
Severity
7.7
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

librechat librechatLibreChat: Incomplete Fix for CVE-2025-7105 — /api/convos/duplicate Lacks Rate Limiting Applied to /api/convos/fork

Risk 38
Severity
6.5
First published (updated )

librechat librechatLibreChat: Missing Resource Parameter Validation in MCP OAuth Flow

Risk 66
Severity
9.3
First published (updated )

LibreChatLibreChat: 2FA Backup Code Regeneration Without OTP Verification Allows 2FA Bypass

Risk 48
Severity
7.1
First published (updated )

LibreChatLibreChat: 2FA Re-enrollment Allows Full Account 2FA Takeover Without OTP Verification

Risk 60
Severity
8.1
First published (updated )

librechat librechatLibreChat: Shared-agent editor can globally delete owner's file records — breaks owner's other private agents

Risk 60
Severity
5.7
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

librechat LibreChat MCP ServerLibreChat Shared MCP Server View Leaks Decrypted Admin Secrets

Risk 38
Severity
6.5
First published (updated )

librechat librechatLibreChat Exfiltrates Server Secrets via MCP Server URL Injection

Risk 68
Severity
9.6
First published (updated )

librechat librechatLibreChat has IDOR in API Keys Management that allows any authenticated user to overwrite other users' API keys

Risk 48
Severity
7.1
First published (updated )

librechat librechatLibreChat Affected by Arbitrary File Write via `execute_code` Artifact Filename Traversal

Risk 37
Severity
6.3
First published (updated )

librechat librechatLibreChat's MCP Server Header Injection Enables OAuth Token Theft

Risk 38
Severity
6.8
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

librechat librechatLibreChat's IDOR in SSE Stream Subscription Allows Reading Other Users' Chats

Risk 32
Severity
5.3
First published (updated )

librechat librechatLibreChat Server-Side Request Forgery using DNS resolution

Risk 44
Severity
7.7
First published (updated )

librechat librechatLibreChat has SSRF protection bypass via IPv4-mapped IPv6 normalization in isPrivateIP

Risk 55
Severity
8.5
First published (updated )

librechat librechatIn LibreChat 0.8.1-rc2, a logged-in user obtains a JWT for both the LibreChat API and the RAG API.

Risk 55
Severity
9
EPSS
0.05%
First published (updated )

LibreChatLibreChat RAG API Authentication Bypass

Risk 73
Severity
8
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

oss-sec[SBA-ADV-20251205-01] LibChat 0.8.1-rc2 RAG API Authentication Bypass

librechat LibreChat RAG APILibreChat RAG API, version 0.7.0, contains a log-injection vulnerability that allows attackers to forge log entries.

Risk 31
Severity
7.5
EPSS
0.07%
First published (updated )

LibreChatLibreChat Denial of Service (DoS) via Unhandled Exception in DELETE /api/convos

Risk 27
Severity
6.5
EPSS
0.05%
First published (updated )

librechat librechatLibreChat MCP OAuth callback does not validate browser session — allows token theft via redirect link

Risk 36
Severity
7.6
EPSS
0.03%
First published (updated )

librechat librechatLibreChat MCP Stdio Remote Command Execution

Risk 59
Severity
9.9
EPSS
0.04%
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

librechat librechatLibreChat is vulnerable to Server-Side Request Forgery due to missing restrictions

Risk 66
Severity
9.1
First published (updated )

librechat librechatLibreChat has Insufficient Access Control for Agent Permission Queries

Risk 22
Severity
4.3
First published (updated )

librechat librechatLibreChat has Insufficient Access Control for Agent Files

Risk 48
Severity
7.1
First published (updated )

npm/librechatLibreChat's lack of JSON parsing error handling can lead to XSS

Risk 38
Severity
6.1
First published (updated )

librechatLibreChat's Improper Input Validation in Prompt Creation API Enables Unauthorized Permission Changes

Risk 38
Severity
6.5
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203