Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6673
Adobe 6383
Ibm 6286
Cisco 5751
Debian 3919
Mozilla 2886
Apache 2864
Redhat 2586
HIGH 7.5
CVE-2025-8849
LibreChat version 0.7.9 is vulnerable to a Denial of Service (DoS) attack due to unbounded parameter values in the `/api/memories` endpoint. The `key…
Librechat
Patch available
HIGH 8.8
CVE-2025-8850
In danny-avila/librechat version 0.7.9, there is an insecure API design issue in the 2-Factor Authentication (2FA) flow. The system allows users to d…
Librechat
Patch available
MEDIUM 5.4
CVE-2025-8848
A vulnerability in danny-avila/librechat version 0.7.9 allows for HTML injection via the Accept-Language header. When a logged-in user sends an HTTP …
Librechat
No fix yet
HIGH 7.5
CVE-2025-7104
A mass assignment vulnerability exists in danny-avila/librechat, affecting all versions. This vulnerability allows attackers to manipulate sensitive …
Librechat
0.7.9+
MEDIUM 5.3
CVE-2025-7106
danny-avila/librechat is affected by an authorization bypass vulnerability due to improper access control checks. The `checkAccess` function in `api/…
Librechat
0.7.9+
HIGH 7.5
CVE-2025-54868
LibreChat is a ChatGPT clone with additional features. In versions 0.0.6 through 0.7.7-rc1, an exposed testing endpoint allows reading arbitrary chat…
Librechat
0.7.8+
MEDIUM 5.3
CVE-2024-12580
A vulnerability in danny-avila/librechat prior to version 0.7.6 allows for logs debug injection. The parameters sessionId, fileId, userId, and file_i…
Librechat
0.7.6+
HIGH 8.8
CVE-2024-11170
A vulnerability in danny-avila/librechat version git 81f2936 allows for path traversal due to improper sanitization of file paths by the multer middl…
Librechat
0.7.6+
HIGH 7.5
CVE-2024-11169
An unhandled exception in danny-avila/librechat version 3c94ff2 can lead to a server crash. The issue occurs when the fs module throws an exception w…
Librechat
0.7.6+
HIGH 7.5
CVE-2024-11171
In danny-avila/librechat version git 0c2a583, there is an improper input validation vulnerability. The application uses multer middleware for handlin…
Librechat
0.7.6+
HIGH 7.5
CVE-2024-11172
A vulnerability in danny-avila/librechat version git a1647d7 allows an unauthenticated attacker to cause a denial of service by sending a crafted pay…
Librechat
0.7.6+
MEDIUM 6.5
CVE-2024-11173
An unhandled exception in the danny-avila/librechat repository, version git 600d217, can cause the server to crash, leading to a full denial of servi…
Librechat
0.7.6+
MEDIUM 5.3
CVE-2024-11167
An improper access control vulnerability in danny-avila/librechat versions prior to 0.7.6 allows authenticated users to delete other users' prompts v…
Librechat
0.7.6+
CRITICAL 9.1
CVE-2024-10361
An arbitrary file deletion vulnerability exists in danny-avila/librechat version v0.7.5-rc2, specifically within the /api/files endpoint. This vulner…
Librechat
Patch available
MEDIUM 6.5
CVE-2024-10366
An improper access control vulnerability (IDOR) exists in the delete attachments functionality of danny-avila/librechat version v0.7.5-rc2. The endpo…
Librechat
Patch available
MEDIUM 5.4
CVE-2024-10363
In version 0.7.5 of danny-avila/LibreChat, there is an improper access control vulnerability. Users can share, use, and create prompts without being …
Librechat
Patch available
CRITICAL 9.8
CVE-2024-41703
LibreChat through 0.7.4-rc1 has incorrect access control for message updates.
Librechat
after 0.7.3
CRITICAL 9.8
CVE-2024-41704
LibreChat through 0.7.4-rc1 does not validate the normalized pathnames of images.
Librechat
after 0.7.3