PT-2026-31026 · Librechat · Librechat

Logggg2402

·

Published

2026-04-07

·

Updated

2026-04-08

·

CVE-2026-34371

CVSS v3.1

6.3

Medium

VectorAV:N/AC:H/PR:L/UI:N/S:C/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions LibreChat versions prior to 0.8.4
Description LibreChat, a ChatGPT clone, is susceptible to an arbitrary file write due to insufficient sanitization of filenames returned by the execute code sandbox. Specifically, the name field from the sandbox is directly used to construct the destination path for code-generated artifacts without proper validation. This allows a user triggering the execute code function to write files to arbitrary locations on the server using path traversal sequences (e.g., ../../../../../app/client/dist/poc.txt) within the filename. The server user's privileges are used for the file write operation.
Recommendations Update LibreChat to version 0.8.4 or later.

Exploit

Fix

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-34371

Affected Products

Librechat