Junglewise Threat Intelligence

CVE-2026-54030: LibreChat token theft via missing OAuth resource validation in MCP

CVE-2026-54030 · Severity: high · CVSS 8 · Published 2026-06-25

Technologies: LibreChat. Vendors: LibreChat.

Executive brief

LibreChat is an open-source interface for interacting with various AI models. A security flaw in how it handles connections to third-party AI services (MCP servers) allows a malicious server to trick the application into sending sensitive login tokens to the wrong destination. If a user connects to a compromised or malicious server, an attacker could steal their access tokens and impersonate them on legitimate AI platforms, potentially leading to unauthorized data access or account takeover.

Technical details

A vulnerability exists in LibreChat's Model Context Protocol (MCP) OAuth implementation due to a failure to adhere to RFC 9728 validation requirements. Specifically, the application does not verify that the 'resource' parameter returned in OAuth Protected Resource metadata matches the configured MCP server URL. An attacker can host a malicious MCP server that, when connected to by a victim, provides metadata pointing to a legitimate resource. Because LibreChat fails to validate this mismatch in 'packages/api/src/mcp/oauth/handler.ts', it initiates an OAuth flow that results in a valid access token for a legitimate service being sent to the attacker's server. This allows for full impersonation of the victim on the legitimate service. The issue is fixed in version 0.8.5.

Affected products

  • danny-avila LibreChat < 0.8.5

Timeline

  • 2026-06-02: advisory: GitHub advisory published by vendor
  • 2026-06-25: disclosed: CVE published to NVD
  • 2026-06-25: patched: Fix released in version 0.8.5

References

Related threats