CVE-2026-22252 is a critical vulnerability affecting LibreChat, a ChatGPT clone, prior to version 0.8.2-rc2. It allows an authenticated attacker to execute arbitrary shell commands as root within the container via a single API request due to a lack of validation in the MCP stdio transport. With a CVSS score of 9.9 (CRITICAL), this vulnerability presents a severe risk, enabling complete compromise of the affected system. There is no evidence of active exploitation, and no public exploit code (Metasploit, Nuclei, ExploitDB) is currently available, though it has garnered some community discussion.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
0.8.2CPE matchmatch criteria | cpe:2.3:a:librechat:librechat:0.8.2:rc1:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 1.0 Bluesky, 0.5 Mastodon, and 1.6 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.