LibreChat is a ChatGPT clone with additional features. Version 0.8.1-rc2 does not enforce proper access control for file uploads to an agents file context and file search. An authenticated attacker with access to the agent ID can change the behavior of arbitrary agents by uploading new files to the file context or file search, even if they have no permissions for this agent. This issue is fixed in version 0.8.2-rc2.
Metrics
Affected Vendors & Products
References
History
Thu, 08 Jan 2026 10:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Librechat
Librechat librechat |
|
| Vendors & Products |
Librechat
Librechat librechat |
Wed, 07 Jan 2026 22:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 07 Jan 2026 21:00:00 +0000
Status: PUBLISHED
Assigner: GitHub_M
Published: 2026-01-07T20:49:00.454Z
Updated: 2026-01-07T21:33:56.352Z
Reserved: 2025-12-29T18:00:37.183Z
Link: CVE-2025-69220
Updated: 2026-01-07T21:33:53.044Z
Status : Awaiting Analysis
Published: 2026-01-07T21:15:59.547
Modified: 2026-01-08T18:08:54.147
Link: CVE-2025-69220
No data.