Librechat
This hub aggregates every CVE we track for Librechat, a product in the oss libraries space. Use it to gauge the current risk picture and drill into individual advisories.
51
CVEs tracked
6
Critical
19
High
0
In CISA KEV
Severity distribution
MEDIUM25HIGH19CRITICAL6LOW1
Monthly trend
0
0
0
0
0
0
11
0
0
0
0
1
3
3
1
3
4
0
9
1
0
13
0
0
2024-092026-08
Latest CVEs
The 15 most recently published vulnerabilities affecting Librechat.
- CVE-2026-54024LibreChat: Incomplete Fix for CVE-2024-11171 — Conversation Import Multer Instance Missing File Size Limits6.5
- CVE-2026-54025LibreChat: Stored XSS via unescaped image alt text in markdown artifact preview5.4
- CVE-2026-54027LibreChat: Image Upload Route Bypasses Agent Permission Check — Incomplete Fix for File Upload Authorization6.5
- CVE-2026-54029LibreChat: IDOR in Message Deletion — Incomplete Fix for CVE-2024-41703 Leaves deleteMessages() Without User Filter5.3
- CVE-2026-54033LibreChat: SSRF via User-Provided Custom Endpoint baseURL — no private IP validation on user-configured API base URLs7.7
- CVE-2026-54037LibreChat: Incomplete Fix for CVE-2025-7105 — /api/convos/duplicate Lacks Rate Limiting Applied to /api/convos/fork6.5
- CVE-2026-54030LibreChat: Missing Resource Parameter Validation in MCP OAuth Flow8.0
- CVE-2026-54040LibreChat: 2FA Backup Code Regeneration Without OTP Verification Allows 2FA Bypass5.9
- CVE-2026-54036LibreChat: 2FA Re-enrollment Allows Full Account 2FA Takeover Without OTP Verification5.3
- CVE-2026-44654LibreChat: Shared-agent editor can globally delete owner's file records — breaks owner's other private agents8.1
- CVE-2026-44653LibreChat Shared MCP Server View Leaks Decrypted Admin Secrets6.5
- CVE-2026-32625LibreChat Exfiltrates Server Secrets via MCP Server URL Injection9.6
- CVE-2026-31942LibreChat has IDOR in API Keys Management that allows any authenticated user to overwrite other users' API keys7.1
- CVE-2026-34371LibreChat Affected by Arbitrary File Write via `execute_code` Artifact Filename Traversal6.3
- CVE-2026-31951LibreChat's MCP Server Header Injection Enables OAuth Token Theft6.8
Product normalization is registry-driven with AI assist and human review. How it works