CRITICAL🇵🇱 Wersja polska

CVE-2026-22252

CVSS 9.1v3.1pub. 2026-01-12upd. 2026-01-15

LibreChat is a ChatGPT clone with additional features. Prior to v0.8.2-rc2, LibreChat's MCP stdio transport accepts arbitrary commands without validation, allowing any authenticated user to execute shell commands as root inside the container through a single API request. This vulnerability is fixed in v0.8.2-rc2.

🤖 AI Analysis
How it works

The MCP stdio transport component in LibreChat accepts and executes arbitrary system commands without any validation of their content. An authenticated user can submit a specially crafted API request containing a malicious shell command. This command is executed directly by the process running with root privileges in the container, without any verification or filtering.

Impact

An attacker with a user account can gain full control over the container with root privileges, including the ability to read and modify all data, execute arbitrary code (RCE), and potentially perform lateral movement to other resources accessible from the container level.

Mitigation & patch

LibreChat should be updated to version v0.8.2-rc2 or newer, where the vulnerability has been fixed. Patch details are available in the vendor references (GitHub commit 211b39f3113d4e6ecab84be0a83f4e9c9dea127f).

Who is affected

LibreChat in all versions before v0.8.2-rc2

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
  • Librechat

    APP
    Librechat
    0.8.2
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
Container
CWE
References

Related vulnerabilities

CVE-2026-32625CRITICAL9.6PL ✓same product

LibreChat: wyciek zmiennych środowiskowych przez konfigurację MCP

CVE-2025-69222CRITICAL9.1PL ✓same product

SSRF w LibreChat — brak ograniczeń funkcji Actions w domyślnej konfiguracji

CVE-2024-10361CRITICAL9.1PL ✓same product

LibreChat: path traversal umożliwiający usunięcie dowolnych plików

CVE-2024-41703CRITICAL9.8PL ✓same product

LibreChat — nieprawidłowa kontrola dostępu przy aktualizacji wiadomości

CVE-2024-41704CRITICAL9.8PL ✓same product

Path Traversal w LibreChat — brak walidacji ścieżek obrazów