Executive brief
LibreChat is an open-source platform that allows users to interact with various AI models through a unified interface. A security flaw allows any logged-in user to upload files to AI "agents" owned by other users without permission. This could allow an attacker to tamper with the behavior of another person's AI assistant or clutter their workspace with unauthorized data.
Technical details
A missing authorization check in the 'POST /api/files/images' endpoint allows authenticated users to upload files to any agent's 'tool_resources' (such as context or execute_code) regardless of ownership. While a previous security patch implemented permission checks for the general '/api/files' route, the image-specific route was overlooked and continues to call 'processAgentFileUpload' without verifying if the requester has EDIT permissions for the target 'agent_id'. An attacker can exploit this to inject arbitrary files into a victim's agent configuration, leading to resource pollution or manipulation of the agent's operational context. The vulnerability is addressed in version 0.8.4-rc1.
Affected products
- danny-avila LibreChat < 0.8.4-rc1
Timeline
- 2026-06-02: advisory: GitHub Security Advisory published
- 2026-06-25: disclosed: NVD publication date