Vulnerability index

Browse CVEs

48 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

HIGH 7.5 CVE-2025-8849 LibreChat version 0.7.9 is vulnerable to a Denial of Service (DoS) attack due to unbounded parameter values in the `/api/memories` endpoint. The `key… Librechat Patch available Fix from $1,9502025-10-31 HIGH 8.8 CVE-2025-8850 In danny-avila/librechat version 0.7.9, there is an insecure API design issue in the 2-Factor Authentication (2FA) flow. The system allows users to d… Librechat Patch available Fix from $1,9502025-10-30 MEDIUM 5.4 CVE-2025-8848 A vulnerability in danny-avila/librechat version 0.7.9 allows for HTML injection via the Accept-Language header. When a logged-in user sends an HTTP … Librechat No fix yet Fix from $1,6002025-10-22 HIGH 7.5 CVE-2025-7104 A mass assignment vulnerability exists in danny-avila/librechat, affecting all versions. This vulnerability allows attackers to manipulate sensitive … Librechat 0.7.9+ Fix from $1,9502025-09-29 MEDIUM 5.3 CVE-2025-7106 danny-avila/librechat is affected by an authorization bypass vulnerability due to improper access control checks. The `checkAccess` function in `api/… Librechat 0.7.9+ Fix from $1,6002025-09-23 HIGH 7.5 CVE-2025-54868 LibreChat is a ChatGPT clone with additional features. In versions 0.0.6 through 0.7.7-rc1, an exposed testing endpoint allows reading arbitrary chat… Librechat 0.7.8+ Fix from $1,9502025-08-05 MEDIUM 5.3 CVE-2024-12580 A vulnerability in danny-avila/librechat prior to version 0.7.6 allows for logs debug injection. The parameters sessionId, fileId, userId, and file_i… Librechat 0.7.6+ Fix from $1,6002025-03-20 HIGH 8.8 CVE-2024-11170 A vulnerability in danny-avila/librechat version git 81f2936 allows for path traversal due to improper sanitization of file paths by the multer middl… Librechat 0.7.6+ Fix from $1,9502025-03-20 HIGH 7.5 CVE-2024-11169 An unhandled exception in danny-avila/librechat version 3c94ff2 can lead to a server crash. The issue occurs when the fs module throws an exception w… Librechat 0.7.6+ Fix from $1,9502025-03-20 HIGH 7.5 CVE-2024-11171 In danny-avila/librechat version git 0c2a583, there is an improper input validation vulnerability. The application uses multer middleware for handlin… Librechat 0.7.6+ Fix from $1,9502025-03-20 HIGH 7.5 CVE-2024-11172 A vulnerability in danny-avila/librechat version git a1647d7 allows an unauthenticated attacker to cause a denial of service by sending a crafted pay… Librechat 0.7.6+ Fix from $1,9502025-03-20 MEDIUM 6.5 CVE-2024-11173 An unhandled exception in the danny-avila/librechat repository, version git 600d217, can cause the server to crash, leading to a full denial of servi… Librechat 0.7.6+ Fix from $1,6002025-03-20 MEDIUM 5.3 CVE-2024-11167 An improper access control vulnerability in danny-avila/librechat versions prior to 0.7.6 allows authenticated users to delete other users' prompts v… Librechat 0.7.6+ Fix from $1,6002025-03-20 CRITICAL 9.1 CVE-2024-10361 An arbitrary file deletion vulnerability exists in danny-avila/librechat version v0.7.5-rc2, specifically within the /api/files endpoint. This vulner… Librechat Patch available Fix from $2,3002025-03-20 MEDIUM 6.5 CVE-2024-10366 An improper access control vulnerability (IDOR) exists in the delete attachments functionality of danny-avila/librechat version v0.7.5-rc2. The endpo… Librechat Patch available Fix from $1,6002025-03-20 MEDIUM 5.4 CVE-2024-10363 In version 0.7.5 of danny-avila/LibreChat, there is an improper access control vulnerability. Users can share, use, and create prompts without being … Librechat Patch available Fix from $1,6002025-03-20 CRITICAL 9.8 CVE-2024-41703 LibreChat through 0.7.4-rc1 has incorrect access control for message updates. Librechat after 0.7.3 Fix from $2,3002024-07-22 CRITICAL 9.8 CVE-2024-41704 LibreChat through 0.7.4-rc1 does not validate the normalized pathnames of images. Librechat after 0.7.3 Fix from $2,3002024-07-22