CVE-2025-66451Medium· 6.5▾ SunlitLibreChat is a ChatGPT clone with additional features. In versions 0.8.0 and below, when creating prompts, JSON requests are sent to define and modify the prompts via PATCH endpoint for prompt groups (/api/prompts/groups/:groupId). Howev…
▾ Sunlit zone — Low / medium · no exploitation signal
impact 35.8 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
0.3%
LibreChat is a ChatGPT clone with additional features. In versions 0.8.0 and below, when creating prompts, JSON requests are sent to define and modify the prompts via PATCH endpoint for prompt groups (/api/prompts/groups/:groupId). However, the request bodies are not sufficiently validated for proper input, enabling users to modify prompts in a way that was not intended as part of the front end system. The patchPromptGroup function passes req.body directly to updatePromptGroup() without filtering sensitive fields. This issue is fixed in version 0.8.1.
librechat < 0.8.1Upgrade past the affected range:
librechat 0.8.1Connected by shared product, vendor, weakness, or advisory.
CVE-2025-66201High· 8.1LibreChat is a ChatGPT clone with additional features
CVE-2025-8849High· 7.5LibreChat version 0.7.9 is vulnerable to a Denial of Service (DoS) attack due to unbounded parameter values in the `/api/memories` endpoint
CVE-2025-8850High· 8.8In danny-avila/librechat version 0.7.9, there is an insecure API design issue in the 2-Factor Authentication (2FA) flow
CVE-2025-66452Medium· 6.1LibreChat is a ChatGPT clone with additional features
CVE-2025-66450Medium· 5.4LibreChat is a ChatGPT clone with additional features
CVE-2025-69222Critical· 9.1LibreChat is a ChatGPT clone with additional features