CRITICAL🇵🇱 Wersja polska

CVE-2025-69222

CVSS 9.1v3.1pub. 2026-01-07upd. 2026-01-15

LibreChat is a ChatGPT clone with additional features. Version 0.8.1-rc2 is prone to a server-side request forgery (SSRF) vulnerability due to missing restrictions of the Actions feature in the default configuration. LibreChat enables users to configure agents with predefined instructions and actions that can interact with remote services via OpenAPI specifications, supporting various HTTP methods, parameters, and authentication methods including custom headers. By default, there are no restrictions on accessible services, which means agents can also access internal components like the RAG API included in the default Docker Compose setup. This issue is fixed in version 0.8.1-rc2.

🤖 AI Analysis
How it works

LibreChat allows users to configure agents with predefined instructions and actions that can communicate with remote services via OpenAPI specification — supporting various HTTP methods, parameters, and authentication methods, including custom headers. In the default configuration, no restrictions are imposed on available services, allowing agents to send requests to internal network components such as RAG API. An authenticated user can therefore configure an agent to indirectly query internal resources that are inaccessible from outside.

Impact

An attacker with regular user privileges can obtain unauthorized access to internal services and network resources (high impact on confidentiality), and potentially modify data or disrupt the operation of internal components (limited impact on integrity and availability).

Mitigation & patch

The vulnerability was fixed in version 0.8.2-rc2. LibreChat should be updated to version 0.8.2-rc2 or newer according to information published by the vendor. As additional security, it is advisable to implement network restrictions limiting the scope of services available to agents.

Who is affected

LibreChat version 0.8.1-rc2 — particularly instances running with the default Docker Compose configuration with Actions functionality enabled.

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:L
  • Librechat

    APP
    Librechat
    0.8.1
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
SSRFContainer
CWE
References

Related vulnerabilities

CVE-2026-32625CRITICAL9.6PL ✓same product

LibreChat: wyciek zmiennych środowiskowych przez konfigurację MCP

CVE-2026-22252CRITICAL9.1PL ✓same product

LibreChat: RCE jako root przez MCP stdio transport bez walidacji poleceń

CVE-2024-10361CRITICAL9.1PL ✓same product

LibreChat: path traversal umożliwiający usunięcie dowolnych plików

CVE-2024-41703CRITICAL9.8PL ✓same product

LibreChat — nieprawidłowa kontrola dostępu przy aktualizacji wiadomości

CVE-2024-41704CRITICAL9.8PL ✓same product

Path Traversal w LibreChat — brak walidacji ścieżek obrazów