PT-2026-1932 · Librechat · Librechat

CVE-2025-69220

·

Published

2026-01-07

·

Updated

2026-01-07

CVSS v3.1

7.1

High

VectorAV:N/AC:H/PR:L/UI:N/S:C/C:N/I:H/A:L
Name of the Vulnerable Software and Affected Versions LibreChat versions prior to 0.8.2-rc2
Description LibreChat, a ChatGPT clone, does not properly control access when uploading files to an agent's file context or during file searches in version 0.8.1-rc2. An authenticated attacker who knows an agent ID can modify the behavior of agents by uploading files, even without proper permissions. The issue involves improper access control related to file uploads and searches within the agent's file context.
Recommendations Update to version 0.8.2-rc2 or later.

Exploit

Fix

Missing Authorization

Improper Access Control

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-69220
GHSA-XCMF-RPMH-HG59

Affected Products

Librechat