PT-2025-12139 · Danny Avila · Librechat
Published
2025-03-20
·
Updated
2025-03-21
·
CVE-2024-12580
CVSS v3.1
5.3
Medium
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
danny-avila/librechat versions prior to 0.7.6
Description
A vulnerability in the software allows for logs debug injection. The parameters
sessionId, fileId, userId, and file id in the "/code/download/:sessionId/:fileId" and "/download/:userId/:file id" API endpoints are not validated or filtered, leading to potential log injection attacks. This can cause distortion of monitoring and investigation information, evade detection from security systems, and create difficulties in maintenance and operation.Recommendations
For versions prior to 0.7.6, update to version 0.7.6 or later to resolve the issue.
As a temporary workaround, consider validating and filtering the
sessionId, fileId, userId, and file id parameters in the affected API endpoints to prevent log injection attacks.Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Librechat