PT-2025-44458 · Librechat · Librechat

Published

2025-10-30

·

Updated

2025-11-19

·

CVE-2025-8850

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions librechat version 0.7.9
Description The software has an insecure API design in the 2-Factor Authentication (2FA) flow. The system permits users to disable 2FA without a valid One-Time Password (OTP) or backup code, circumventing the verification process. This occurs because the backend does not validate the OTP or backup code when the API endpoint /api/auth/2fa/disable is accessed. An authenticated user can exploit this to weaken their account security.
Recommendations Ensure proper validation of OTP or backup codes when accessing the /api/auth/2fa/disable endpoint.

Fix

Weakness Enumeration

Related Identifiers

CVE-2025-8850

Affected Products

Librechat