PT-2025-37108 · Danny Avila · Librechat
CVE-2025-6088
·
Publicado
2025-06-14
·
Atualizado
2025-10-16
CVSS v3.1
4.2
Média
| Vetor | AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:L |
Name of the Vulnerable Software and Affected Versions:
danny-avila/librechat version 0.7.8
Description:
Improper authorization controls in the conversation sharing feature allow unauthorized access to other users' conversations if the conversation ID is known. Conversation IDs, while generated server-side as UUIDv4, can be obtained from sources like server-side access logs, browser history, or screenshots. Exploitation involves accessing the
/api/share/conversationID endpoint without proper authorization checks, granting read-only access to another user's conversations.Recommendations:
Update to version 0.7.9-rc1 or later.
Exploit
Correção
Improper Authorization
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Librechat