PT-2026-1932 · Librechat · Librechat
Published
2026-01-07
·
Updated
2026-01-07
·
CVE-2025-69220
CVSS v3.1
7.1
High
| Vector | AV:N/AC:H/PR:L/UI:N/S:C/C:N/I:H/A:L |
Name of the Vulnerable Software and Affected Versions
LibreChat versions prior to 0.8.2-rc2
Description
LibreChat, a ChatGPT clone, does not properly control access when uploading files to an agent's file context or during file searches in version 0.8.1-rc2. An authenticated attacker who knows an agent ID can modify the behavior of agents by uploading files, even without proper permissions. The issue involves improper access control related to file uploads and searches within the agent's file context.
Recommendations
Update to version 0.8.2-rc2 or later.
Exploit
Fix
Missing Authorization
Improper Access Control
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Librechat