PT-2026-1933 · Librechat · Librechat

Published

2026-01-07

·

Updated

2026-01-07

·

CVE-2025-69221

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions LibreChat versions prior to 0.8.2-rc2
Description LibreChat, a ChatGPT clone with additional features, does not properly enforce access control when querying agent permissions in version 0.8.1-rc2. An authenticated attacker can read the permissions of arbitrary agents, even if they do not have permissions for that agent. The software allows the configuration of agents with predefined instructions and context. While private agents are intended to be invisible to other users, an attacker knowing the agent ID can access their permissions, including permissions assigned to other users.
Recommendations Update to version 0.8.2-rc2 or later.

Exploit

Fix

Missing Authorization

Improper Access Control

Weakness Enumeration

Related Identifiers

CVE-2025-69221
GHSA-5CCX-4R3H-9QC7

Affected Products

Librechat