---
id: CVE-2025-69222
title: LibreChat is a ChatGPT clone with additional features
summary: >-
  LibreChat is a ChatGPT clone with additional features. Version 0.8.1-rc2 is
  prone to a server-side request forgery (SSRF)

  vulnerability due to missing restrictions of the Actions feature in the
  default configuration. LibreChat enables us…
severity: critical
cvss: 9.1
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:L'
cwe:
  - CWE-918
vendor: librechat
product: librechat
affected:
  - librechat = 0.8.1
published: '2026-01-07'
updated: '2026-09-30'
sourceUpdated: '2026-09-30T23:10:00.237'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-69222'
references:
  - url: >-
      https://github.com/danny-avila/LibreChat/commit/3b41e392ba5c0d603c1737d8582875e04eaa6e02
    label: security-advisories@github.com
  - url: 'https://github.com/danny-avila/LibreChat/releases/tag/v0.8.2-rc2'
    label: security-advisories@github.com
  - url: >-
      https://github.com/danny-avila/LibreChat/security/advisories/GHSA-rgjq-4q58-m3q8
    label: security-advisories@github.com
tags:
  - nvd
epss: 0.0465
epssPercentile: 0.91439
ingestedAt: '2026-09-30T23:29:32.558Z'
---

## Overview

LibreChat is a ChatGPT clone with additional features. Version 0.8.1-rc2 is prone to a server-side request forgery (SSRF)
vulnerability due to missing restrictions of the Actions feature in the default configuration. LibreChat enables users to configure agents with predefined instructions and actions that can interact with remote services via OpenAPI specifications, supporting various HTTP methods, parameters, and authentication methods including custom headers. By default, there are no restrictions on accessible services, which means agents can also access internal components like the RAG API included in the default Docker Compose setup. This issue is fixed in version 0.8.1-rc2.

## Affected

- `librechat = 0.8.1`

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
