PT-2026-28429 · Librechat · Librechat

Danny-Avila

·

Publicado

2026-03-27

·

Atualizado

2026-03-28

·

CVE-2026-31943

CVSS v3.1

8.5

Alta

VetorAV:N/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:N
Name of the Vulnerable Software and Affected Versions LibreChat versions prior to 0.8.3
Description LibreChat is a ChatGPT clone with additional features. Prior to version 0.8.3, the isPrivateIP() function in packages/api/src/auth/domain.ts does not correctly identify IPv4-mapped IPv6 addresses in their hex-normalized form. This allows any authenticated user to bypass Server-Side Request Forgery (SSRF) protection. Successful exploitation enables the server to make HTTP requests to internal network resources, including cloud metadata services (e.g., AWS 169.254.169.254), loopback, and RFC1918 ranges. The vulnerable function is isPrivateIP(). The affected API endpoint is not explicitly mentioned.
Recommendations Upgrade to version 0.8.3 to resolve this issue.

Exploit

Correção

SSRF

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2026-31943
GHSA-W5R7-4F94-VP4C

Produtos afetados

Librechat