PT-2024-35440 · Librechat · Librechat

·

CVE-2024-52787

·

Published

2024-11-25

·

Updated

2026-07-07

CVSS v3.1

9.1

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions libre-chat version 0.0.6
Description The issue allows attackers to execute a path traversal via supplying a crafted filename in an uploaded file, specifically in the upload documents method.
Recommendations For libre-chat version 0.0.6, consider restricting the use of the upload documents method until a patch is available to prevent path traversal attacks. Avoid using crafted filenames in uploaded files to minimize the risk of exploitation.

Exploit

Fix

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2024-52787
GHSA-3864-RP2M-2QFJ
PYSEC-2026-1537

Affected Products

Librechat