CRITICAL🇵🇱 Wersja polska

CVE-2026-32625

CVSS 9.6v3.1pub. 2026-06-02upd. 2026-07-22

LibreChat is an enhanced ChatGPT clone that supports multiple AI providers. In versions up to and including 0.8.3, the Model Context Protocol (MCP) server integration resolves ${VAR} placeholders against the server's process.env during Zod schema validation of user-supplied MCP server URLs. Any authenticated user can create a malicious MCP server configuration with a URL pointing to an attacker-controlled domain containing environment variable references, causing the LibreChat server to connect to the attacker's server and transmit critical secrets such as CREDS_KEY, CREDS_IV, JWT_SECRET, and MONGO_URI in the request URL. This enables full compromise of the installation's cryptographic materials and database credentials without requiring administrative privileges. This is patched in version 0.8.4-rc1.

🤖 AI Analysis
How it works

Integration with Model Context Protocol (MCP) server resolves placeholders in the format ${VAR} to values of server process environment variables (process.env) during Zod schema validation for user-supplied MCP server URLs. The attacker creates a malicious MCP configuration pointing to a domain under their control, placing environment variable references in the URL. The LibreChat server connects to the attacker's server, transmitting secret variable values such as CREDS_KEY, CREDS_IV, JWT_SECRET, and MONGO_URI in the URL.

Impact

The attacker gains access to critical cryptographic secrets and database credentials, enabling complete takeover of the installation — data decryption, JWT token forgery, and direct access to MongoDB database.

Mitigation & patch

Update LibreChat to version 0.8.4-rc1 or later, in which the vulnerability has been patched. After updating, perform rotation of all potentially exposed secrets: CREDS_KEY, CREDS_IV, JWT_SECRET, and MONGO_URI credentials.

Who is affected

LibreChat versions up to and including 0.8.3

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N
  • Librechat

    APP
    Librechat
    < 0.8.4
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
CWE
References

Related vulnerabilities

CVE-2026-22252CRITICAL9.1PL ✓same product

LibreChat: RCE jako root przez MCP stdio transport bez walidacji poleceń

CVE-2025-69222CRITICAL9.1PL ✓same product

SSRF w LibreChat — brak ograniczeń funkcji Actions w domyślnej konfiguracji

CVE-2024-10361CRITICAL9.1PL ✓same product

LibreChat: path traversal umożliwiający usunięcie dowolnych plików

CVE-2024-41703CRITICAL9.8PL ✓same product

LibreChat — nieprawidłowa kontrola dostępu przy aktualizacji wiadomości

CVE-2024-41704CRITICAL9.8PL ✓same product

Path Traversal w LibreChat — brak walidacji ścieżek obrazów