Vendor
LibreChat vulnerabilities
Updated . Rebuilt every hour.
Junglewise Threat Intelligence has tracked 15 vulnerabilities in LibreChat: 0 in the last 7 days and 0 in the last 90 days, 1 of them critical and 0 exploited in the wild. The most recent, CVE-2026-54040, was published on 25 June 2026. 1 technology has a page of its own.
- Last 7 days
- 0
- Last 90 days
- 0
- Critical, all time
- 1
- Exploited in the wild
- 0
About LibreChat
An open-source AI chat interface that supports multiple large language model providers and self-hosting.
LibreChat technologies
Latest LibreChat vulnerabilities
- CVE-2026-54040: LibreChat 2FA bypass via unauthenticated backup code regenerationmediumCVSS 5.9
- CVE-2026-54037: LibreChat resource exhaustion via missing rate limiting in duplicate endpointmediumCVSS 6.5
- CVE-2026-54033: LibreChat SSRF via custom endpoint baseURLhighCVSS 7.7
- CVE-2026-54030: LibreChat token theft via missing OAuth resource validation in MCPhighCVSS 8
- CVE-2026-54029: danny-avila LibreChat IDOR in message deletion endpointmediumCVSS 5.3
- CVE-2026-54027: LibreChat missing authorization in image upload endpointmediumCVSS 6.5
- CVE-2026-54025: LibreChat stored XSS in markdown artifact previewmediumCVSS 5.4
- CVE-2026-54024: LibreChat resource exhaustion in conversation import endpointmediumCVSS 6.5
- CVE-2026-54036: danny-avila LibreChat 2FA takeover via re-enrollment endpointmediumCVSS 5.3
- CVE-2026-44654: LibreChat incorrect authorization in file deletion endpointinfoCVSS 5.7
- CVE-2026-44653: LibreChat sensitive information disclosure in MCP server APImediumCVSS 6.5
- CVE-2026-32625: LibreChat environment variable exfiltration in MCP server integrationcriticalCVSS 9.6
- CVE-2026-31942: LibreChat IDOR in API keys management endpointhighCVSS 7.1
- CVE-2026-34371: LibreChat path traversal in execute_code artifact persistencemediumCVSS 6.3EPSS 0.3%
- CVE-2026-4276: LibreChat RAG API log injection in file_id parameterhighCVSS 7.5EPSS 0.1%
Most severe LibreChat vulnerabilities
Exploited in the wild first, then by severity and CVSS score.
- CVE-2026-32625: LibreChat environment variable exfiltration in MCP server integrationcriticalCVSS 9.6
- CVE-2026-54030: LibreChat token theft via missing OAuth resource validation in MCPhighCVSS 8
- CVE-2026-54033: LibreChat SSRF via custom endpoint baseURLhighCVSS 7.7
- CVE-2026-4276: LibreChat RAG API log injection in file_id parameterhighCVSS 7.5EPSS 0.1%
- CVE-2026-31942: LibreChat IDOR in API keys management endpointhighCVSS 7.1
- CVE-2026-54037: LibreChat resource exhaustion via missing rate limiting in duplicate endpointmediumCVSS 6.5
- CVE-2026-54027: LibreChat missing authorization in image upload endpointmediumCVSS 6.5
- CVE-2026-54024: LibreChat resource exhaustion in conversation import endpointmediumCVSS 6.5
- CVE-2026-44653: LibreChat sensitive information disclosure in MCP server APImediumCVSS 6.5
- CVE-2026-34371: LibreChat path traversal in execute_code artifact persistencemediumCVSS 6.3EPSS 0.3%
Vulnerabilities per week
The last 13 weeks, by the week each vulnerability was published.
| Week of | Bar | Vulns | Critical |
|---|---|---|---|
| 29 Jun 2026 | 0 | 0 | |
| 6 Jul 2026 | 0 | 0 | |
| 13 Jul 2026 | 0 | 0 | |
| 20 Jul 2026 | 0 | 0 | |
| 27 Jul 2026 | 0 | 0 | |
| 3 Aug 2026 | 0 | 0 | |
| 10 Aug 2026 | 0 | 0 | |
| 17 Aug 2026 | 0 | 0 | |
| 24 Aug 2026 | 0 | 0 | |
| 31 Aug 2026 | 0 | 0 | |
| 7 Sep 2026 | 0 | 0 | |
| 14 Sep 2026 | 0 | 0 | |
| 21 Sep 2026 | 0 | 0 |
How this is built
Junglewise Threat Intelligence collects vulnerabilities from NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories, and matches each one to the technologies and vendors it affects. Dates are the date a vulnerability was published, in UTC.
The pages are rebuilt from the database every hour. Frozen weekly and monthly reports never change once published, so they can be cited.
Use this data
The same data is at https://junglewise.ai/threats/vendors/librechat.json, for scripts and language models. It is free to reuse under CC BY 4.0 with a link back to this page.
Cite as: Junglewise Threat Intelligence, "LibreChat vulnerabilities", https://junglewise.ai/threats/vendors/librechat, 26 September 2026.