LibreChat is a ChatGPT clone with additional features. Version 0.8.1-rc2 is prone to a server-side request forgery (SSRF) vulnerability due to missing restrictions of the Actions feature in the default configuration. LibreChat enables users to configure agents with predefined instructions and actions that can interact with remote services via OpenAPI specifications, supporting various HTTP methods, parameters, and authentication methods including custom headers. By default, there are no restrictions on accessible services, which means agents can also access internal components like the RAG API included in the default Docker Compose setup. This issue is fixed in version 0.8.1-rc2.
LibreChat allows users to configure agents with predefined instructions and actions that can communicate with remote services via OpenAPI specification — supporting various HTTP methods, parameters, and authentication methods, including custom headers. In the default configuration, no restrictions are imposed on available services, allowing agents to send requests to internal network components such as RAG API. An authenticated user can therefore configure an agent to indirectly query internal resources that are inaccessible from outside.
An attacker with regular user privileges can obtain unauthorized access to internal services and network resources (high impact on confidentiality), and potentially modify data or disrupt the operation of internal components (limited impact on integrity and availability).
The vulnerability was fixed in version 0.8.2-rc2. LibreChat should be updated to version 0.8.2-rc2 or newer according to information published by the vendor. As additional security, it is advisable to implement network restrictions limiting the scope of services available to agents.
LibreChat version 0.8.1-rc2 — particularly instances running with the default Docker Compose configuration with Actions functionality enabled.
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:LLibrechat
APPLibrechat0.8.1
Related vulnerabilities
LibreChat: wyciek zmiennych środowiskowych przez konfigurację MCP
LibreChat: RCE jako root przez MCP stdio transport bez walidacji poleceń
LibreChat: path traversal umożliwiający usunięcie dowolnych plików
LibreChat — nieprawidłowa kontrola dostępu przy aktualizacji wiadomości
Path Traversal w LibreChat — brak walidacji ścieżek obrazów