7.1
/ 10
HIGH
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:N/I:H/A:L
Description
LibreChat is a ChatGPT clone with additional features. Version 0.8.1-rc2 does not enforce proper access control for file uploads to an agents file context and file search. An authenticated attacker with access to the agent ID can change the behavior of arbitrary agents by uploading new files to the file context or file search, even if they have no permissions for this agent. This issue is fixed in version 0.8.2-rc2.
Basic Information
ID
CVE-2025-69220
Source
GitHub_M
Published
Jan 7, 2026 at 20:49
Modified
Jan 7, 2026 at 21:33
Affected Product
Vendor
danny-avila
Product
LibreChat
Version
>= 0.8.1-rc2, < 0.8.2-rc2
Affected Versions
danny-avila LibreChat >= 0.8.1-rc2, < 0.8.2-rc2
CWE Classification
References
- github.com /danny-avila/LibreChat/security/advisories/GHSA-xcmf-rpmh-hg59
- github.com /danny-avila/LibreChat/commit/4b9c6ab1cb9de626736de700c7981f38be08d237
- cwe.mitre.org /data/definitions/284.html
- cwe.mitre.org /data/definitions/862.html
- github.com /danny-avila/LibreChat/releases/tag/v0.8.2-rc2
- owasp.org /Top10/A01_2021-Broken_Access_Control
- owasp.org /www-project-web-security-testing-guide/v42/4-Web_Application_Security_Testing/05-Authorization_Testing/02-Testing_for_Bypassing_Authorization_Schema.html
- raw.githubusercontent.com /OWASP/ASVS/v5.0.0/5.0/OWASP_Application_Security_Verification_Standard_5.0.0_en.pdf