Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Librechat

First CVE: Jul 22, 2024Active for: 2 yearsTotal CVEs: 51
46.9
VTI Score
High

Librechat is an open-source conversational AI platform that aggregates and manages access to multiple large language model endpoints, presenting a focused but security-critical application whose role in handling user authentication and API proxying creates substantial leverage for privilege-escalation attacks. Vulnerabilities affecting the vendor skew toward serious outcomes, with an elevated share reaching critical severity, reflecting the high stakes of authentication and authorization flaws in a system that mediates user access to sensitive model APIs and data. The vulnerability pattern is remarkably durable: recurring weakness classes center on improper access control, authorization bypass through user-controlled keys, missing authorization checks, and server-side request forgery, all of which exploit the application's position as an intermediary between users and protected backend services. These flaws are characteristic of auth-layer and API-proxy codebases and amplify risk because a single bypass can grant unauthorized access to model usage, user conversations, or internal systems. Defenders should treat Librechat deployments as high-value targets for privilege-escalation attempts and prioritize prompt patching of authorization-related disclosures; current severity and exploitation counts are shown alongside this summary.

FAUCET AI Generated
51
Total CVEs
More Total CVEs than 98% of tracked vendors
17.0
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 100% of tracked vendors
7.0
Avg CVSS Score
Higher Avg CVSS Score than 50% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Librechat over time

Volume of CVEsAvg CVSS Base Score
First CVE
Jul 22, 2024
2 years ago
Most Recent CVE
Jun 25, 2026
29 days ago

Products(1 total)

Top CVEs

Signals from CVEs in this vendor scope (51 CVEs).

51 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2026-32625CRITICAL
LibreChat is an enhanced ChatGPT clone that supports multiple AI providers. In versions up to and including 0.8.3, the Model Context Protocol (MCP) server integration resolves ${VA
Jun 2, 20269.643NONO
CVE-2026-54030CRITICAL
LibreChat is an enhanced ChatGPT clone that supports multiple AI providers. Prior to 0.8.5, LibreChat's MCP OAuth implementation does not validate that the resource parameter from
Jun 25, 20269.337NONO
CVE-2026-31942HIGH
LibreChat is an enhanced ChatGPT clone that supports multiple AI providers. In versions up to and including 0.7.6, an Insecure Direct Object Reference (IDOR) vulnerability exists i
Jun 2, 20267.134NONO
CVE-2026-44654HIGH
LibreChat is an enhanced ChatGPT clone that supports multiple AI providers. In versions up to and including 0.8.3, a shared-agent editor can delete file records through `DELETE /ap
Jun 2, 20268.133NONO
CVE-2026-22252CRITICAL
LibreChat is a ChatGPT clone with additional features. Prior to v0.8.2-rc2, LibreChat's MCP stdio transport accepts arbitrary commands without validation, allowing any authenticate
Jan 12, 20269.932NONO
CVE-2025-69222HIGH
LibreChat is a ChatGPT clone with additional features. Version 0.8.1-rc2 is prone to a server-side request forgery (SSRF) vulnerability due to missing restrictions of the Actions f
Jan 7, 20268.132NONO
CVE-2026-54036HIGH
LibreChat is an enhanced ChatGPT clone that supports multiple AI providers. Prior to 0.8.4-rc1, the GET /api/auth/2fa/enable endpoint can be called by an authenticated user (or att
Jun 25, 20268.131NONO
CVE-2026-54033MEDIUM
LibreChat is an enhanced ChatGPT clone that supports multiple AI providers. Prior to 0.8.4-rc1, LibreChat allows users to configure custom OpenAI-compatible API endpoints by settin
Jun 25, 20266.530NONO
CVE-2026-31943HIGH
LibreChat is a ChatGPT clone with additional features. Prior to version 0.8.3, `isPrivateIP()` in `packages/api/src/auth/domain.ts` fails to detect IPv4-mapped IPv6 addresses in th
Mar 27, 20268.530NONO
CVE-2026-54029MEDIUM
LibreChat is an enhanced ChatGPT clone that supports multiple AI providers. Prior to 0.8.4-rc1, the DELETE /api/messages/:conversationId/:messageId endpoint allows any authenticate
Jun 25, 20266.529NONO
View all 51 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products51 CVEs
47%
37%
14%
Severity distribution among all CVEs352,294 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local0 (0.0%)
Network49 (96.1%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network2 (3.9%)
Attack Complexity
Low47 (92.2%)
High4 (7.8%)
Unknown0 (0.0%)
User Interaction
None43 (84.3%)
Unknown0 (0.0%)
Required8 (15.7%)
Privileges Required
Low35 (68.6%)
High0 (0.0%)
None16 (31.4%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (51 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
1 CVE
2.0% of CVEs· 95th percentile
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Librechat.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Librechat — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Librechat's Products

View all 5 CNAs →

Top CWEs