Junglewise Threat Intelligence

CVE-2026-54033: LibreChat SSRF via custom endpoint baseURL

CVE-2026-54033 · Severity: high · CVSS 7.7 · Published 2026-06-25

Technologies: LibreChat. Vendors: LibreChat.

Executive brief

LibreChat is an open-source interface that allows users to connect to various AI models like ChatGPT. A security flaw allows authenticated users to redirect the application's internal requests to unintended locations by providing a malicious "Base URL" in the settings. This could allow an attacker to access sensitive internal company data, steal cloud credentials, or probe private network services that are not normally exposed to the internet.

Technical details

A Server-Side Request Forgery (SSRF) vulnerability exists in LibreChat due to insufficient validation of user-supplied 'baseURL' configurations for custom endpoints. While the application implements SSRF protections for certain tools, these checks (such as private IP filtering and DNS pinning) are bypassed when constructing requests in components like OllamaClient.js and Runs/methods.js. An authenticated attacker can provide internal network addresses (e.g., loopback or cloud metadata services like 169.254.169.254) as a baseURL. This allows the attacker to perform internal service discovery, access sensitive metadata, or forward configured API keys to unauthorized internal listeners. The vulnerability is addressed in version 0.8.4-rc1.

Affected products

  • danny-avila LibreChat < 0.8.4-rc1

Timeline

  • 2026-06-02: advisory: GitHub Security Advisory published
  • 2026-06-25: disclosed: NVD publication date
  • 2026-08-04: patched: Fixed in version 0.8.4-rc1

References

Related threats