CVE-2024-10359 is a medium-severity vulnerability affecting danny-avila/librechat v0.7.5-rc2, where a mass assignment flaw in preset creation allows an authenticated attacker to manipulate user IDs. This enables an attacker to inject a different user ID into a preset object, causing it to appear in another user's interface, impacting both data integrity and confidentiality. The vulnerability has a CVSS score of 4.6 (Medium) due to its low attack complexity and limited impact. There is no evidence of active exploitation, public exploit code, or significant community discussion surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
0.7.5CPE matchmatch criteria | cpe:2.3:a:librechat:librechat:0.7.5:rc2:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.