PT-2025-37108 · Danny Avila · Librechat
Published
2025-06-14
·
Updated
2025-10-16
·
CVE-2025-6088
CVSS v3.1
4.2
Medium
| Vector | AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:L |
Name of the Vulnerable Software and Affected Versions:
danny-avila/librechat version 0.7.8
Description:
Improper authorization controls in the conversation sharing feature allow unauthorized access to other users' conversations if the conversation ID is known. Conversation IDs, while generated server-side as UUIDv4, can be obtained from sources like server-side access logs, browser history, or screenshots. Exploitation involves accessing the
/api/share/conversationID endpoint without proper authorization checks, granting read-only access to another user's conversations.Recommendations:
Update to version 0.7.9-rc1 or later.
Fix
Improper Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Librechat