CVE-2024-11169
- EPSS 0.79%
- Veröffentlicht 20.03.2025 10:09:59
- Zuletzt bearbeitet 15.07.2025 16:45:29
An unhandled exception in danny-avila/librechat version 3c94ff2 can lead to a server crash. The issue occurs when the fs module throws an exception while handling file uploads. An unauthenticated user can trigger this exception by sending a specially...
CVE-2024-11167
- EPSS 0.1%
- Veröffentlicht 20.03.2025 10:09:49
- Zuletzt bearbeitet 15.07.2025 11:15:24
An improper access control vulnerability in danny-avila/librechat versions prior to 0.7.6 allows authenticated users to delete other users' prompts via the groupid parameter. This issue occurs because the endpoint does not verify whether the provided...
CVE-2024-10366
- EPSS 0.07%
- Veröffentlicht 20.03.2025 10:09:37
- Zuletzt bearbeitet 15.07.2025 11:15:23
An improper access control vulnerability (IDOR) exists in the delete attachments functionality of danny-avila/librechat version v0.7.5-rc2. The endpoint does not verify whether the provided attachment ID belongs to the current user, allowing any auth...
CVE-2024-12580
- EPSS 0.08%
- Veröffentlicht 20.03.2025 10:09:16
- Zuletzt bearbeitet 14.07.2025 17:56:24
A vulnerability in danny-avila/librechat prior to version 0.7.6 allows for logs debug injection. The parameters sessionId, fileId, userId, and file_id in the /code/download/:sessionId/:fileId and /download/:userId/:file_id APIs are not validated or f...
CVE-2024-10361
- EPSS 0.37%
- Veröffentlicht 20.03.2025 10:09:09
- Zuletzt bearbeitet 15.10.2025 13:15:35
An arbitrary file deletion vulnerability exists in danny-avila/librechat version v0.7.5-rc2, specifically within the /api/files endpoint. This vulnerability arises from improper input validation, allowing path traversal techniques to delete arbitrary...
CVE-2024-11170
- EPSS 2.88%
- Veröffentlicht 20.03.2025 10:08:59
- Zuletzt bearbeitet 15.07.2025 16:45:15
A vulnerability in danny-avila/librechat version git 81f2936 allows for path traversal due to improper sanitization of file paths by the multer middleware. This can lead to arbitrary file write and potentially remote code execution. The issue is fixe...
CVE-2024-52787
- EPSS 0.28%
- Veröffentlicht 25.11.2024 18:15:13
- Zuletzt bearbeitet 27.11.2024 17:15:14
An issue in the upload_documents method of libre-chat v0.0.6 allows attackers to execute a path traversal via supplying a crafted filename in an uploaded file.
CVE-2024-41703
- EPSS 0.14%
- Veröffentlicht 22.07.2024 05:15:03
- Zuletzt bearbeitet 21.11.2024 09:33:00
LibreChat through 0.7.4-rc1 has incorrect access control for message updates.
CVE-2024-41704
- EPSS 0.28%
- Veröffentlicht 22.07.2024 05:15:03
- Zuletzt bearbeitet 21.11.2024 09:33:00
LibreChat through 0.7.4-rc1 does not validate the normalized pathnames of images.