PT-2025-48355 · Librechat · Librechat

Published

2025-11-29

·

Updated

2025-12-22

·

CVE-2025-66201

CVSS v4.0

8.6

High

VectorAV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions LibreChat versions prior to 0.8.1-rc2
Description LibreChat, a ChatGPT clone with additional features, contains a Server-side Request Forgery (SSRF) issue in its "Actions" feature. An authenticated user with access to this feature can exploit this by submitting specially crafted OpenAPI specifications, causing the Large Language Model (LLM) to utilize these actions. This allows access to URLs accessible only to the LibreChat server, potentially including cloud metadata services, which could lead to server impersonation.
Recommendations Update LibreChat to version 0.8.1-rc2 or later.

Exploit

Fix

SSRF

RCE

Weakness Enumeration

Related Identifiers

CVE-2025-66201
GHSA-7M2Q-FJWR-5X8V

Affected Products

Librechat