Vulnerabilities
Vulnerable Software
Librechat:  >> Librechat  >> 0.0.1  Security Vulnerabilities
A vulnerability in danny-avila/librechat version git a1647d7 allows an unauthenticated attacker to cause a denial of service by sending a crafted payload to the server. The middleware `checkBan` is not surrounded by a try-catch block, and an unhandled exception will cause the server to crash. This issue is fixed in version 0.7.6.
CVSS Score
7.5
EPSS Score
0.009
Published
2025-03-20
An unhandled exception in the danny-avila/librechat repository, version git 600d217, can cause the server to crash, leading to a full denial of service. This issue occurs when certain API endpoints receive malformed input, resulting in an uncaught exception. Although a valid JWT is required to exploit this vulnerability, LibreChat allows open registration, enabling unauthenticated attackers to create an account and perform the attack. The issue is fixed in version 0.7.6.
CVSS Score
6.5
EPSS Score
0.008
Published
2025-03-20
LibreChat through 0.7.4-rc1 has incorrect access control for message updates.
CVSS Score
9.8
EPSS Score
0.004
Published
2024-07-22
LibreChat through 0.7.4-rc1 does not validate the normalized pathnames of images.
CVSS Score
9.8
EPSS Score
0.007
Published
2024-07-22


Contact Us

Shodan ® - All rights reserved