{"id":"CVE-2025-7104","title":"A mass assignment vulnerability exists in danny-avila/librechat, affecting all versions","summary":"A mass assignment vulnerability exists in danny-avila/librechat, affecting all versions. This vulnerability allows attackers to manipulate sensitive fields by automatically binding user-provided data to internal object properties or data…","severity":"high","cvss":7.5,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N","cwe":["CWE-915"],"vendor":"librechat","product":"librechat","affected":["librechat < 0.7.9"],"patched":["librechat 0.7.9"],"published":"2025-09-29","updated":"2026-10-09","sourceUpdated":"2026-10-09T09:10:00.213","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2025-7104","references":[{"url":"https://github.com/danny-avila/librechat/commit/a37bf6719cfbc2de270f7d87b6b85d87cc1768db","label":"security@huntr.dev"},{"url":"https://huntr.com/bounties/32a175c4-7543-4503-a3d0-7880abd1826b","label":"security@huntr.dev"}],"tags":["nvd"],"epss":0.003,"epssPercentile":0.20844,"ingestedAt":"2026-10-09T09:31:00.984Z","slug":"CVE-2025-7104","body":"## Overview\n\nA mass assignment vulnerability exists in danny-avila/librechat, affecting all versions. This vulnerability allows attackers to manipulate sensitive fields by automatically binding user-provided data to internal object properties or database fields without proper filtering. As a result, any extra fields in the request body are included in agentData and passed to the database layer, allowing overwriting of any field in the schema, such as author, access_level, isCollaborative, and projectIds. Additionally, the Object.Prototype can be polluted due to the use of Object.assign with spread operators.\n\n## Affected\n\n- `librechat < 0.7.9`\n\n## Remediation\n\nUpgrade past the affected range:\n\n- `librechat 0.7.9`","depth":"twilight","depthScore":41,"depthScoreParts":{"impact":41.3,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[]}