PT-2026-45882 · Librechat · Librechat

Logggg2402

·

Published

2026-06-02

·

Updated

2026-06-03

·

CVE-2026-44653

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions LibreChat versions prior to 0.8.4
Description Users with only VIEW access to an MCP server can retrieve decrypted admin-managed secrets. This occurs through the endpoints "/api/mcp/servers" and "/api/mcp/servers/:serverName", where the returned configuration includes plaintext values for the variables apiKey.key and oauth.client secret. This allows unauthorized users to exfiltrate provider credentials.
Recommendations Update to version 0.8.4. Redact apiKey.key and oauth.client secret from all API responses. Avoid returning decrypted admin-managed secrets to non-owners, using boolean presence indicators or server-side placeholders instead.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-44653

Affected Products

Librechat