Junglewise Threat Intelligence

CVE-2026-44654: LibreChat incorrect authorization in file deletion endpoint

CVE-2026-44654 · Severity: info · CVSS 5.7 · Published 2026-06-02

Technologies: LibreChat. Vendors: LibreChat.

Executive brief

LibreChat is an AI interface that allows users to create and share custom AI agents. A flaw in the system allows users who have been granted permission to edit a shared agent to delete files that do not belong to them. This can result in the permanent deletion of files used by the owner's private agents, causing those private agents to malfunction and leading to data loss.

Technical details

An incorrect authorization vulnerability (CWE-863) exists in the `DELETE /api/files` endpoint of LibreChat versions up to 0.8.3. The endpoint fails to properly scope file deletion requests to the specific agent context provided. An attacker with 'agent_editor' permissions on a shared agent can submit a deletion request for a `file_id` that is also referenced by the owner's private agents. Because the deletion is processed globally rather than being restricted to the shared agent's scope, the file record is removed entirely, leaving the owner's private agents with stale, unresolvable file references. This allows an attacker to impact resources they are not authorized to access. The issue is addressed in version 0.8.4 (and 0.8.5).

Affected products

  • danny-avila LibreChat <= 0.8.3

Timeline

  • 2026-03-17: other: Vulnerability verified in lab environment
  • 2026-06-02: disclosed: Advisory published by maintainer
  • 2026-06-02: advisory: NVD record published

References

Related threats