CVE-2025-66450Medium· 5.4▾ SunlitLibreChat is a ChatGPT clone with additional features. In versions 0.8.0 and below, when a user posts a question, the iconURL parameter of the POST request can be modified by an attacker. The malicious code is then stored in the chat whi…
▾ Sunlit zone — Low / medium · no exploitation signal
impact 29.7 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
0.2%
LibreChat is a ChatGPT clone with additional features. In versions 0.8.0 and below, when a user posts a question, the iconURL parameter of the POST request can be modified by an attacker. The malicious code is then stored in the chat which can then be shared to other users. When sharing chats with a potentially malicious “tracker”, resources loaded can lead to loss of privacy for users who view the chat link that is sent to them. This issue is fixed in version 0.8.1.
librechat < 0.8.1Upgrade past the affected range:
librechat 0.8.1Connected by shared product, vendor, weakness, or advisory.
CVE-2025-8849High· 7.5LibreChat version 0.7.9 is vulnerable to a Denial of Service (DoS) attack due to unbounded parameter values in the `/api/memories` endpoint
CVE-2025-8850High· 8.8In danny-avila/librechat version 0.7.9, there is an insecure API design issue in the 2-Factor Authentication (2FA) flow
CVE-2025-66452Medium· 6.1LibreChat is a ChatGPT clone with additional features
CVE-2025-66451Medium· 6.5LibreChat is a ChatGPT clone with additional features
CVE-2025-66201High· 8.1LibreChat is a ChatGPT clone with additional features
CVE-2025-69222Critical· 9.1LibreChat is a ChatGPT clone with additional features