PT-2026-2183 · Librechat · Librechat

Retpoline

·

Published

2026-01-10

·

Updated

2026-04-24

·

CVE-2026-22252

CVSS v3.1

9.9

Critical

VectorAV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions LibreChat versions prior to 0.8.2-rc2
Description LibreChat is a ChatGPT clone with additional features. Prior to version 0.8.2-rc2, the MCP stdio transport does not validate commands, allowing authenticated users to execute shell commands as root inside the container via a single API request. The vulnerability allows for remote code execution. The affected component is the MCP stdio transport. The API request allows arbitrary command execution. The vulnerable parameter is not specified.
Recommendations LibreChat versions prior to 0.8.2-rc2 should be updated to version 0.8.2-rc2.

Exploit

Fix

RCE

Improper Authorization

Weakness Enumeration

Related Identifiers

CVE-2026-22252
GHSA-CXHJ-J78R-P88F

Affected Products

Librechat