Ad

CVE-2025-69221

MEDIUM CVSS 3.1: 4.3 EPSS 0.03%
Updated Jan 15, 2026
Librechat
Parameter Value
CVSS 4.3 (MEDIUM)
Fixed In 0.8.2
Type CWE-862 (Missing Authorization), CWE-284 (Improper Access Control)
Vendor Librechat
Public PoC No

LibreChat is a ChatGPT clone with additional features. Version 0.8.1-rc2 does not enforce proper access control when querying agent permissions. An authenticated attacker can read the permissions of arbitrary agents, even if they have no permissions for this agent. LibreChat allows the configuration of agents that have a predefined set of instructions and context.

Private agents are not visible to other users. However, if an attacker knows the agent ID, they can read the permissions of the agent including the permissions individually assigned to other users. This issue is fixed in version 0.8.2-rc2.

Attack Parameters

Attack Vector
Network
Can be exploited remotely
Attack Complexity
Low
Easy to exploit
Privileges Required
Low
Basic privileges needed
User Interaction
None
No user interaction needed

Impact Assessment

Confidentiality
Low
Partial data leak
Integrity
None
No data modification
Availability
None
No disruption

CVSS Vector v3.1

Vulnerable Products 2

Configuration From (including) Up to (excluding)
Librechat Librechat
cpe:2.3:a:librechat:librechat:0.8.1:-:*:*:*:*:*:*
Librechat Librechat
cpe:2.3:a:librechat:librechat:0.8.1:rc1:*:*:*:*:*:*