PT-2026-1932 · Librechat · Librechat
CVE-2025-69220
·
Publicado
2026-01-07
·
Atualizado
2026-01-07
CVSS v3.1
7.1
Alta
| Vetor | AV:N/AC:H/PR:L/UI:N/S:C/C:N/I:H/A:L |
Name of the Vulnerable Software and Affected Versions
LibreChat versions prior to 0.8.2-rc2
Description
LibreChat, a ChatGPT clone, does not properly control access when uploading files to an agent's file context or during file searches in version 0.8.1-rc2. An authenticated attacker who knows an agent ID can modify the behavior of agents by uploading files, even without proper permissions. The issue involves improper access control related to file uploads and searches within the agent's file context.
Recommendations
Update to version 0.8.2-rc2 or later.
Exploit
Correção
Missing Authorization
Improper Access Control
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Librechat