PT-2025-31902 · Unknown+1 · Meilisearch+1

Joel-Sass

·

Published

2025-08-05

·

Updated

2025-08-26

·

CVE-2025-54868

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions LibreChat versions 0.0.6 through 0.7.7-rc1
Description LibreChat, a ChatGPT clone, contains an exposed testing endpoint that allows unauthorized access to chats stored in the Meilisearch engine. The /api/search/test endpoint does not enforce proper access controls, enabling the retrieval of chats belonging to arbitrary users.
Recommendations Update to version 0.7.7 or later.

Exploit

Fix

Improper Authorization

Weakness Enumeration

Related Identifiers

CVE-2025-54868
GHSA-P5J8-M4WH-FFMW

Affected Products

Librechat
Meilisearch