Librechat is an open-source conversational AI platform that aggregates and manages access to multiple large language model endpoints, presenting a focused but security-critical application whose role in handling user authentication and API proxying creates substantial leverage for privilege-escalation attacks. Vulnerabilities affecting the vendor skew toward serious outcomes, with an elevated share reaching critical severity, reflecting the high stakes of authentication and authorization flaws in a system that mediates user access to sensitive model APIs and data. The vulnerability pattern is remarkably durable: recurring weakness classes center on improper access control, authorization bypass through user-controlled keys, missing authorization checks, and server-side request forgery, all of which exploit the application's position as an intermediary between users and protected backend services. These flaws are characteristic of auth-layer and API-proxy codebases and amplify risk because a single bypass can grant unauthorized access to model usage, user conversations, or internal systems. Defenders should treat Librechat deployments as high-value targets for privilege-escalation attempts and prioritize prompt patching of authorization-related disclosures; current severity and exploitation counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Librechat over time
Signals from CVEs in this vendor scope (51 CVEs).
51 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-32625CRITICAL LibreChat is an enhanced ChatGPT clone that supports multiple AI providers. In versions up to and including 0.8.3, the Model Context Protocol (MCP) server integration resolves ${VA | Jun 2, 2026 | 9.6 | 43 | NO | NO |
CVE-2026-54030CRITICAL LibreChat is an enhanced ChatGPT clone that supports multiple AI providers. Prior to 0.8.5, LibreChat's MCP OAuth implementation does not validate that the resource parameter from | Jun 25, 2026 | 9.3 | 37 | NO | NO |
CVE-2026-31942HIGH LibreChat is an enhanced ChatGPT clone that supports multiple AI providers. In versions up to and including 0.7.6, an Insecure Direct Object Reference (IDOR) vulnerability exists i | Jun 2, 2026 | 7.1 | 34 | NO | NO |
CVE-2026-44654HIGH LibreChat is an enhanced ChatGPT clone that supports multiple AI providers. In versions up to and including 0.8.3, a shared-agent editor can delete file records through `DELETE /ap | Jun 2, 2026 | 8.1 | 33 | NO | NO |
CVE-2026-22252CRITICAL LibreChat is a ChatGPT clone with additional features. Prior to v0.8.2-rc2, LibreChat's MCP stdio transport accepts arbitrary commands without validation, allowing any authenticate | Jan 12, 2026 | 9.9 | 32 | NO | NO |
CVE-2025-69222HIGH LibreChat is a ChatGPT clone with additional features. Version 0.8.1-rc2 is prone to a server-side request forgery (SSRF)
vulnerability due to missing restrictions of the Actions f | Jan 7, 2026 | 8.1 | 32 | NO | NO |
CVE-2026-54036HIGH LibreChat is an enhanced ChatGPT clone that supports multiple AI providers. Prior to 0.8.4-rc1, the GET /api/auth/2fa/enable endpoint can be called by an authenticated user (or att | Jun 25, 2026 | 8.1 | 31 | NO | NO |
CVE-2026-54033MEDIUM LibreChat is an enhanced ChatGPT clone that supports multiple AI providers. Prior to 0.8.4-rc1, LibreChat allows users to configure custom OpenAI-compatible API endpoints by settin | Jun 25, 2026 | 6.5 | 30 | NO | NO |
CVE-2026-31943HIGH LibreChat is a ChatGPT clone with additional features. Prior to version 0.8.3, `isPrivateIP()` in `packages/api/src/auth/domain.ts` fails to detect IPv4-mapped IPv6 addresses in th | Mar 27, 2026 | 8.5 | 30 | NO | NO |
CVE-2026-54029MEDIUM LibreChat is an enhanced ChatGPT clone that supports multiple AI providers. Prior to 0.8.4-rc1, the DELETE /api/messages/:conversationId/:messageId endpoint allows any authenticate | Jun 25, 2026 | 6.5 | 29 | NO | NO |
Signals from CVEs in this vendor scope (51 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Librechat.
Media articles that mention a CVE ID that affects a product developed by Librechat — matched by CVE ID, not by vendor name.