librechat vulnerabilities
CVEs whose affected-version data names the librechat package. Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.
3 CVEsRSS
CVE-2025-69222Critical· 9.1LibreChat is a ChatGPT clone with additional features
LibreChat is a ChatGPT clone with additional features. Version 0.8.1-rc2 is prone to a server-side request forgery (SSRF) vulnerability due to missing restrictions of the Actions feature in the default configuration. LibreChat enables us…
CVE-2025-69221Medium· 4.3LibreChat is a ChatGPT clone with additional features
LibreChat is a ChatGPT clone with additional features. Version 0.8.1-rc2 does not enforce proper access control when querying agent permissions. An authenticated attacker can read the permissions of arbitrary agents, even if they have no…
CVE-2025-69220High· 7.1LibreChat is a ChatGPT clone with additional features
LibreChat is a ChatGPT clone with additional features. Version 0.8.1-rc2 does not enforce proper access control for file uploads to an agents file context and file search. An authenticated attacker with access to the agent ID can change …