PT-2025-48355 · Librechat · Librechat
Published
2025-11-29
·
Updated
2025-12-22
·
CVE-2025-66201
CVSS v4.0
8.6
High
| Vector | AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
LibreChat versions prior to 0.8.1-rc2
Description
LibreChat, a ChatGPT clone with additional features, contains a Server-side Request Forgery (SSRF) issue in its "Actions" feature. An authenticated user with access to this feature can exploit this by submitting specially crafted OpenAPI specifications, causing the Large Language Model (LLM) to utilize these actions. This allows access to URLs accessible only to the LibreChat server, potentially including cloud metadata services, which could lead to server impersonation.
Recommendations
Update LibreChat to version 0.8.1-rc2 or later.
Exploit
Fix
SSRF
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Librechat