PT-2025-31902 · Unknown +1 · Meilisearch +1

Joel-Sass

·

Published

2025-08-05

·

Updated

2025-08-05

·

CVE-2025-54868

CVSS v3.1
7.5
VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Name of the Vulnerable Software and Affected Versions:

LibreChat versions 0.0.6 through 0.7.7-rc1

Description:

LibreChat, a ChatGPT clone, contains an exposed testing endpoint that allows unauthorized access to chats stored in the Meilisearch engine. The `/api/search/test` endpoint does not enforce proper access controls, enabling the retrieval of chats belonging to arbitrary users.

Recommendations:

Update to version 0.7.7 or later.

Fix

Improper Authorization

Weakness Enumeration

Related Identifiers

CVE-2025-54868
GHSA-P5J8-M4WH-FFMW

Affected Products

Librechat
Meilisearch