librechat has 3 CVEs on record. The busiest recent month was January 2026 with 3. The median CVSS is 7.1 (high), with 1 rated critical.
CVEs per month
Last 12 months, by publish date
- Exploited share
- 0% vs 1% corpus
- Median CVSS
- 7.1
- Publish → KEV
- —
- Last 90 days
- 0 prev 0
librechat vulnerabilities
CVEs affecting librechat, newest first. Open any entry for full detail, references, and exploit status.
3 CVEsRSS
CVE-2025-69222Critical· 9.1LibreChat is a ChatGPT clone with additional features
LibreChat is a ChatGPT clone with additional features. Version 0.8.1-rc2 is prone to a server-side request forgery (SSRF) vulnerability due to missing restrictions of the Actions feature in the default configuration. LibreChat enables us…
CVE-2025-69221Medium· 4.3LibreChat is a ChatGPT clone with additional features
LibreChat is a ChatGPT clone with additional features. Version 0.8.1-rc2 does not enforce proper access control when querying agent permissions. An authenticated attacker can read the permissions of arbitrary agents, even if they have no…
CVE-2025-69220High· 7.1LibreChat is a ChatGPT clone with additional features
LibreChat is a ChatGPT clone with additional features. Version 0.8.1-rc2 does not enforce proper access control for file uploads to an agents file context and file search. An authenticated attacker with access to the agent ID can change …