Vulnerability index

Browse CVEs

48 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Librechat HIGH 7.5
CVE-2025-8849

LibreChat version 0.7.9 is vulnerable to a Denial of Service (DoS) attack due to unbounded parameter values in the `/api/memories` endpoint. The `key…

Patch available
Fix from $1,950 2025-10-31
Librechat HIGH 8.8
CVE-2025-8850

In danny-avila/librechat version 0.7.9, there is an insecure API design issue in the 2-Factor Authentication (2FA) flow. The system allows users to d…

Patch available
Fix from $1,950 2025-10-30
Librechat MEDIUM 5.4
CVE-2025-8848

A vulnerability in danny-avila/librechat version 0.7.9 allows for HTML injection via the Accept-Language header. When a logged-in user sends an HTTP …

No fix yet
Fix from $1,600 2025-10-22
Librechat HIGH 7.5
CVE-2025-7104

A mass assignment vulnerability exists in danny-avila/librechat, affecting all versions. This vulnerability allows attackers to manipulate sensitive …

Fix: 0.7.9+
Fix from $1,950 2025-09-29
Librechat MEDIUM 5.3
CVE-2025-7106

danny-avila/librechat is affected by an authorization bypass vulnerability due to improper access control checks. The `checkAccess` function in `api/…

Fix: 0.7.9+
Fix from $1,600 2025-09-23
Librechat HIGH 7.5
CVE-2025-54868

LibreChat is a ChatGPT clone with additional features. In versions 0.0.6 through 0.7.7-rc1, an exposed testing endpoint allows reading arbitrary chat…

Fix: 0.7.8+
Fix from $1,950 2025-08-05
Librechat MEDIUM 5.3
CVE-2024-12580

A vulnerability in danny-avila/librechat prior to version 0.7.6 allows for logs debug injection. The parameters sessionId, fileId, userId, and file_i…

Fix: 0.7.6+
Fix from $1,600 2025-03-20
Librechat HIGH 8.8
CVE-2024-11170

A vulnerability in danny-avila/librechat version git 81f2936 allows for path traversal due to improper sanitization of file paths by the multer middl…

Fix: 0.7.6+
Fix from $1,950 2025-03-20
Librechat HIGH 7.5
CVE-2024-11169

An unhandled exception in danny-avila/librechat version 3c94ff2 can lead to a server crash. The issue occurs when the fs module throws an exception w…

Fix: 0.7.6+
Fix from $1,950 2025-03-20
Librechat HIGH 7.5
CVE-2024-11171

In danny-avila/librechat version git 0c2a583, there is an improper input validation vulnerability. The application uses multer middleware for handlin…

Fix: 0.7.6+
Fix from $1,950 2025-03-20
Librechat HIGH 7.5
CVE-2024-11172

A vulnerability in danny-avila/librechat version git a1647d7 allows an unauthenticated attacker to cause a denial of service by sending a crafted pay…

Fix: 0.7.6+
Fix from $1,950 2025-03-20
Librechat MEDIUM 6.5
CVE-2024-11173

An unhandled exception in the danny-avila/librechat repository, version git 600d217, can cause the server to crash, leading to a full denial of servi…

Fix: 0.7.6+
Fix from $1,600 2025-03-20
Librechat MEDIUM 5.3
CVE-2024-11167

An improper access control vulnerability in danny-avila/librechat versions prior to 0.7.6 allows authenticated users to delete other users' prompts v…

Fix: 0.7.6+
Fix from $1,600 2025-03-20
Librechat CRITICAL 9.1
CVE-2024-10361

An arbitrary file deletion vulnerability exists in danny-avila/librechat version v0.7.5-rc2, specifically within the /api/files endpoint. This vulner…

Patch available
Fix from $2,300 2025-03-20
Librechat MEDIUM 6.5
CVE-2024-10366

An improper access control vulnerability (IDOR) exists in the delete attachments functionality of danny-avila/librechat version v0.7.5-rc2. The endpo…

Patch available
Fix from $1,600 2025-03-20
Librechat MEDIUM 5.4
CVE-2024-10363

In version 0.7.5 of danny-avila/LibreChat, there is an improper access control vulnerability. Users can share, use, and create prompts without being …

Patch available
Fix from $1,600 2025-03-20
Librechat CRITICAL 9.8
CVE-2024-41703

LibreChat through 0.7.4-rc1 has incorrect access control for message updates.

Fix: after 0.7.3
Fix from $2,300 2024-07-22
Librechat CRITICAL 9.8
CVE-2024-41704

LibreChat through 0.7.4-rc1 does not validate the normalized pathnames of images.

Fix: after 0.7.3
Fix from $2,300 2024-07-22