CVE 9.1 CRITICAL

LibreChat is vulnerable to Server-Side Request Forgery due to missing restrictions_CVE-2025-69222

9.1 / 10
CRITICAL
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:L

Description

LibreChat is a ChatGPT clone with additional features. Version 0.8.1-rc2 is prone to a server-side request forgery (SSRF)
vulnerability due to missing restrictions of the Actions feature in the default configuration. LibreChat enables users to configure agents with predefined instructions and actions that can interact with remote services via OpenAPI specifications, supporting various HTTP methods, parameters, and authentication methods including custom headers. By default, there are no restrictions on accessible services, which means agents can also access internal components like the RAG API included in the default Docker Compose setup. This issue is fixed in version 0.8.1-rc2.

AI Analysis

Server-Side Request Forgery (SSRF) vulnerability due to missing restrictions in the Actions feature

Basic Information

ID CVE-2025-69222
Source GitHub_M
Published Jan 7, 2026 at 21:17
Modified Jan 7, 2026 at 21:34

Affected Product

Vendor danny-avila
Product LibreChat
Version >= 0.8.1-rc2, 0.8.2-rc2
Affected Versions danny-avila LibreChat >= 0.8.1-rc2, 0.8.2-rc2

CWE Classification

AI Assessment

AI Score 9.1 / 10
AI Severity Critical
Vendor danny-avila
Product LibreChat
Version 0.8.1-rc2, 0.8.2-rc2

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.