In version 0.7.5 of danny-avila/LibreChat, there is an improper access control vulnerability. Users can share, use, and create prompts without being granted permission by the admin. This can break application logic and permissions, allowing unauthorized actions.
Metrics
Affected Vendors & Products
References
History
Fri, 11 Jul 2025 20:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Librechat
Librechat librechat |
|
Weaknesses | NVD-CWE-noinfo | |
CPEs | cpe:2.3:a:librechat:librechat:0.7.5:*:*:*:*:*:*:* | |
Vendors & Products |
Librechat
Librechat librechat |
Thu, 20 Mar 2025 19:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Thu, 20 Mar 2025 10:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | In version 0.7.5 of danny-avila/LibreChat, there is an improper access control vulnerability. Users can share, use, and create prompts without being granted permission by the admin. This can break application logic and permissions, allowing unauthorized actions. | |
Title | Improper Access Control in danny-avila/LibreChat | |
Weaknesses | CWE-284 | |
References |
| |
Metrics |
cvssV3_0
|

Status: PUBLISHED
Assigner: @huntr_ai
Published: 2025-03-20T10:10:19.050Z
Updated: 2025-03-20T18:23:18.794Z
Reserved: 2024-10-24T18:59:25.577Z
Link: CVE-2024-10363

Updated: 2025-03-20T17:49:06.252Z

Status : Analyzed
Published: 2025-03-20T10:15:16.630
Modified: 2025-07-11T20:09:44.703
Link: CVE-2024-10363

No data.