LibreChat is a ChatGPT clone with additional features. Prior to v0.8.2-rc2, LibreChat's MCP stdio transport accepts arbitrary commands without validation, allowing any authenticated user to execute shell commands as root inside the container through a single API request. This vulnerability is fixed in v0.8.2-rc2.
The MCP stdio transport component in LibreChat accepts and executes arbitrary system commands without any validation of their content. An authenticated user can submit a specially crafted API request containing a malicious shell command. This command is executed directly by the process running with root privileges in the container, without any verification or filtering.
An attacker with a user account can gain full control over the container with root privileges, including the ability to read and modify all data, execute arbitrary code (RCE), and potentially perform lateral movement to other resources accessible from the container level.
LibreChat should be updated to version v0.8.2-rc2 or newer, where the vulnerability has been fixed. Patch details are available in the vendor references (GitHub commit 211b39f3113d4e6ecab84be0a83f4e9c9dea127f).
LibreChat in all versions before v0.8.2-rc2
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:HLibrechat
APPLibrechat0.8.2
Related vulnerabilities
LibreChat: wyciek zmiennych środowiskowych przez konfigurację MCP
SSRF w LibreChat — brak ograniczeń funkcji Actions w domyślnej konfiguracji
LibreChat: path traversal umożliwiający usunięcie dowolnych plików
LibreChat — nieprawidłowa kontrola dostępu przy aktualizacji wiadomości
Path Traversal w LibreChat — brak walidacji ścieżek obrazów