PT-2026-1932 · Librechat · Librechat

CVE-2025-69220

·

Publicado

2026-01-07

·

Atualizado

2026-01-07

CVSS v3.1

7.1

Alta

VetorAV:N/AC:H/PR:L/UI:N/S:C/C:N/I:H/A:L
Name of the Vulnerable Software and Affected Versions LibreChat versions prior to 0.8.2-rc2
Description LibreChat, a ChatGPT clone, does not properly control access when uploading files to an agent's file context or during file searches in version 0.8.1-rc2. An authenticated attacker who knows an agent ID can modify the behavior of agents by uploading files, even without proper permissions. The issue involves improper access control related to file uploads and searches within the agent's file context.
Recommendations Update to version 0.8.2-rc2 or later.

Exploit

Correção

Missing Authorization

Improper Access Control

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2025-69220
GHSA-XCMF-RPMH-HG59

Produtos afetados

Librechat