PT-2025-44458 · Librechat · Librechat
Published
2025-10-30
·
Updated
2025-11-19
·
CVE-2025-8850
CVSS v3.1
8.8
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
librechat version 0.7.9
Description
The software has an insecure API design in the 2-Factor Authentication (2FA) flow. The system permits users to disable 2FA without a valid One-Time Password (OTP) or backup code, circumventing the verification process. This occurs because the backend does not validate the OTP or backup code when the API endpoint
/api/auth/2fa/disable is accessed. An authenticated user can exploit this to weaken their account security.Recommendations
Ensure proper validation of OTP or backup codes when accessing the
/api/auth/2fa/disable endpoint.Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Librechat