---
id: CVE-2025-69220
title: LibreChat is a ChatGPT clone with additional features
summary: >-
  LibreChat is a ChatGPT clone with additional features. Version 0.8.1-rc2 does
  not enforce proper access control for file uploads to an agents file context
  and file search. An authenticated attacker with access to the agent ID can
  change …
severity: high
cvss: 7.1
cvssVector: 'CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:N/I:H/A:L'
cwe:
  - CWE-284
  - CWE-862
  - CWE-862
vendor: librechat
product: librechat
affected:
  - librechat = 0.8.1
published: '2026-01-07'
updated: '2026-09-30'
sourceUpdated: '2026-09-30T23:10:00.237'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-69220'
references:
  - url: 'https://cwe.mitre.org/data/definitions/284.html'
    label: security-advisories@github.com
  - url: 'https://cwe.mitre.org/data/definitions/862.html'
    label: security-advisories@github.com
  - url: >-
      https://github.com/danny-avila/LibreChat/commit/4b9c6ab1cb9de626736de700c7981f38be08d237
    label: security-advisories@github.com
  - url: 'https://github.com/danny-avila/LibreChat/releases/tag/v0.8.2-rc2'
    label: security-advisories@github.com
  - url: >-
      https://github.com/danny-avila/LibreChat/security/advisories/GHSA-xcmf-rpmh-hg59
    label: security-advisories@github.com
  - url: 'https://owasp.org/Top10/A01_2021-Broken_Access_Control'
    label: security-advisories@github.com
  - url: >-
      https://owasp.org/www-project-web-security-testing-guide/v42/4-Web_Application_Security_Testing/05-Authorization_Testing/02-Testing_for_Bypassing_Authorization_Schema.html
    label: security-advisories@github.com
  - url: >-
      https://raw.githubusercontent.com/OWASP/ASVS/v5.0.0/5.0/OWASP_Application_Security_Verification_Standard_5.0.0_en.pdf
    label: security-advisories@github.com
tags:
  - nvd
epss: 0.00328
epssPercentile: 0.23456
ingestedAt: '2026-09-30T23:29:32.557Z'
---

## Overview

LibreChat is a ChatGPT clone with additional features. Version 0.8.1-rc2 does not enforce proper access control for file uploads to an agents file context and file search. An authenticated attacker with access to the agent ID can change the behavior of arbitrary agents by uploading new files to the file context or file search, even if they have no permissions for this agent. This issue is fixed in version 0.8.2-rc2.

## Affected

- `librechat = 0.8.1`

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
