PT-2026-1932 · Librechat · Librechat

Published

2026-01-07

·

Updated

2026-01-07

·

CVE-2025-69220

CVSS v3.1

7.1

High

VectorAV:N/AC:H/PR:L/UI:N/S:C/C:N/I:H/A:L
Name of the Vulnerable Software and Affected Versions LibreChat versions prior to 0.8.2-rc2
Description LibreChat, a ChatGPT clone, does not properly control access when uploading files to an agent's file context or during file searches in version 0.8.1-rc2. An authenticated attacker who knows an agent ID can modify the behavior of agents by uploading files, even without proper permissions. The issue involves improper access control related to file uploads and searches within the agent's file context.
Recommendations Update to version 0.8.2-rc2 or later.

Exploit

Fix

Missing Authorization

Improper Access Control

Weakness Enumeration

Related Identifiers

CVE-2025-69220
GHSA-XCMF-RPMH-HG59

Affected Products

Librechat