CVE-2025-69222 describes a Server-Side Request Forgery (SSRF) vulnerability in LibreChat version 0.8.1-rc2 and earlier, a ChatGPT clone. The flaw stems from insufficient restrictions within the Actions feature, allowing agents to access internal services like the RAG API. This vulnerability carries a CVSS score of 8.1 (HIGH), indicating a network-exploitable issue with low attack complexity, requiring low privileges, and potentially leading to high impact on confidentiality and integrity. While there is no evidence of active exploitation, public exploit code, or KEV listing, the vulnerability has garnered significant community discussion with 11 mentions, suggesting awareness among security researchers. The issue is resolved in LibreChat version 0.8.1-rc2.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
0.8.1CPE matchmatch criteria | cpe:2.3:a:librechat:librechat:0.8.1:-:*:*:*:*:*:* | ||
0.8.1CPE matchmatch criteria | cpe:2.3:a:librechat:librechat:0.8.1:rc1:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:L
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
LibreChat Server-Side Request Forgery (CVE-2025-69222)
Mar 12, 2026LibreChat Server-Side Request Forgery (CVE-2025-69222)
Mar 12, 2026LibreChat Server-Side Request Forgery (CVE-2025-69222)
Mar 12, 2026