LibreChat is a ChatGPT clone with additional features. Version 0.8.1-rc2 does not enforce proper access control for file uploads to an agent…

cve CVE-2025-69220 1 source, 1 claim · Watch

NVD writes:
LibreChat is a ChatGPT clone with additional features. Version 0.8.1-rc2 does not enforce proper access control for file uploads to an agents file context and file search. An authenticated attacker with access to the agent ID can change the behavior of arbitrary agents by uploading new files to the file context or file search, even if they have no permissions for this agent. This issue is fixed in version 0.8.2-rc2. the claim
Severity
MEDIUM NVD
CVSS
5.9 NVD
Vendor
danny-avila NVD
Product
LibreChat NVD
CWE
CWE-284, CWE-862 NVD

How far exploitation has got

  1. No public code known
  2. Proof of concept
  3. Proof of concept, verified
  4. A Metasploit module
  5. Exploited in the wild
  6. Used in ransomware campaigns

Timeline

2026-01-07first spoke of it: LibreChat is a ChatGPT clone with additional features. Version 0.8.1-rc2 does not enforce proper access control for file uploads to an agents file context and file search. An authenticated attacker with access to the agent ID can change the behavior of arbitrary agents by uploading new files to the file context or file search, even if they have no permissions for this agent. This issue is fixed in version 0.8.2-rc2.NVD

LibreChat is a ChatGPT clone with additional features. Version 0.8.1-rc2 does not enforce proper access control for file uploads to an agents file context and file search. An authenticated attacker with access to the agent ID can change the behavior of arbitrary agents by uploading new files to the file context or file search, even if they have no permissions for this agent. This issue is fixed in version 0.8.2-rc2.

What it is to other things

affectslibrechat/librechat
NVD
made_bylibrechat
NVD

In words only, so not counted until a person confirms one:

made_bydanny_avila
NVD says “danny-avila”
affectsdanny_avila/librechat
NVD says “danny-avila · LibreChat”
Every value, with what each source said and its receipt
PropertySourceSaidMeans here
Automatable
automatable
NVDno
At least one of those steps needs a person.
receipt
Source
NVD
Its words
no
Read by
field:cve.metrics.ssvcV203[].ssvcData.options[].automatable
Said since
2026-10-06 12:29 UTC
Last answered
2026-10-06 12:41 UTC
Original
open at the source
2026-10-06 12:29 UTCno
2026-10-02 12:00 UTC—
What the source handed over
{
  "cve": {
    "affected": [
      {
        "affectedData": [
          {
            "product": "LibreChat",
            "vendor": "danny-avila",
            "versions": [
              {
                "status": "affected",
                "version": ">= 0.8.1-rc2, < 0.8.2-rc2"
              }
            ]
          }
        ],
        "source": "security-advisories@github.com"
      }
    ],
    "configurations": [
      {
        "nodes": [
          {
            "cpeMatch": [
              {
                "criteria": "cpe:2.3:a:librechat:librechat:0.8.1:-:*:*:*:*:*:*",
                "matchCriteriaId": "98BB9E92-2D0E-4975-A966-734F3858551B",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:librechat:librechat:0.8.1:rc1:*:*:*:*:*:*",
                "matchCriteriaId": "8DAB7F45-699A-4383-ABEA-D4374E58EE95",
                "vulnerable": true
              }
            ],
            "negate": false,
            "operator": "OR"
          }
        ]
      }
    ],
    "cveTags": [],
    "descriptions": [
      {
        "lang": "en",
        "value": "LibreChat is a ChatGPT clone with additional features. Version 0.8.1-rc2 does not enforce proper access control for file uploads to an agents file context and file search. An authenticated attacker with access to the agent ID can change the behavior of arbitrary agents by uploading new files to the file context or file search, even if they have no permissions for this agent. This issue is fixed in version 0.8.2-rc2."
      },
      {
        "lang": "es",
        "value": "LibreChat es un clon de ChatGPT con características adicionales. La versión 0.8.1-rc2 no aplica un control de acceso adecuado para la carga de archivos al contexto de archivos de un agente y a la búsqueda de archivos. Un atacante autenticado con acceso al ID del agente puede cambiar el comportamiento de agentes arbitrarios cargando nuevos archivos al contexto de archivos o a la búsqueda de archivos, incluso si no tienen permisos para este agente. Este problema está solucionado en la versión 0.8.2-rc2."
      }
    ],
    "id": "CVE-2025-69220",
    "lastModified": "2026-09-30T23:10:00.237",
    "metrics": {
      "cvssMetricV31": [
        {
          "cvssData": {
            "attackComplexity": "HIGH",
            "attackVector": "NETWORK",
            "availabilityImpact": "LOW",
            "baseScore": 7.1,
            "baseSeverity": "HIGH",
            "confidentialityImpact": "NONE",
            "integrityImpact": "HIGH",
            "privilegesRequired": "LOW",
            "scope": "CHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:N/I:H/A:L",
            "version": "3.1"
          },
          "exploitabilityScore": 1.8,
          "impactScore": 4.7,
          "source": "security-advisories@github.com",
          "type": "Secondary"
        },
        {
          "cvssData": {
            "attackComplexity": "HIGH",
            "attackVector": "NETWORK",
            "availabilityImpact": "NONE",
            "baseScore": 5.9,
            "baseSeverity": "MEDIUM",
            "confidentialityImpact": "NONE",
            "integrityImpact": "HIGH",
            "privilegesRequired": "NONE",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N",
            "version": "3.1"
          },
          "exploitabilityScore": 2.2,
          "impactScore": 3.6,
          "source": "nvd@nist.gov",
          "type": "Primary"
        }
      ],
      "ssvcV203": [
        {
          "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "ssvcData": {
            "id": "CVE-2025-69220",
            "options": [
              {
                "exploitation": "none"
              },
              {
                "automatable": "no"
              },
              {
                "technicalImpact": "partial"
              }
            ],
            "role": "CISA Coordinator",
            "timestamp": "2026-01-07T21:33:29.380614Z",
            "version": "2.0.3"
          }
        }
      ]
    },
    "published": "2026-01-07T21:15:59.547",
    "references": [
      {
        "source": "security-advisories@github.com",
        "tags": [
          "Not Applicable"
        ],
        "url": "https://cwe.mitre.org/data/definitions/284.html"
      },
      {
        "source": "security-advisories@github.com",
        "tags": [
          "Not Applicable"
        ],
        "url": "https://cwe.mitre.org/data/definitions/862.html"
      },
      {
        "source": "security-advisories@github.com",
        "tags": [
          "Patch"
        ],
        "url": "https://github.com/danny-avila/LibreChat/commit/4b9c6ab1cb9de626736de700c7981f38be08d237"
      },
      {
        "source": "security-advisories@github.com",
        "tags": [
          "Release Notes"
        ],
        "url": "https://github.com/danny-avila/LibreChat/releases/tag/v0.8.2-rc2"
      },
      {
        "source": "security-advisories@github.com",
        "tags": [
          "Exploit",
          "Vendor Advisory"
        ],
        "url": "https://github.com/danny-avila/LibreChat/security/advisories/GHSA-xcmf-rpmh-hg59"
      },
      {
        "source": "security-advisories@github.com",
        "tags": [
          "Not Applicable"
        ],
        "url": "https://owasp.org/Top10/A01_2021-Broken_Access_Control"
      },
      {
        "source": "security-advisories@github.com",
        "tags": [
          "Technical Description"
        ],
        "url": "https://owasp.org/www-project-web-security-testing-guide/v42/4-Web_Application_Security_Testing/05-Authorization_Testing/02-Testing_for_Bypassing_Authorization_Schema.html"
      },
      {
        "source": "security-advisories@github.com",
        "tags": [
          "Technical Description"
        ],
        "url": "https://raw.githubusercontent.com/OWASP/ASVS/v5.0.0/5.0/OWASP_Application_Security_Verification_Standard_5.0.0_en.pdf"
      }
    ],
    "sourceIdentifier": "security-advisories@github.com",
    "vulnStatus": "Analyzed",
    "weaknesses": [
      {
        "description": [
          {
            "lang": "en",
            "value": "CWE-284"
          },
          {
            "lang": "en",
            "value": "CWE-862"
          }
        ],
        "source": "security-advisories@github.com",
        "type": "Secondary"
      },
      {
        "description": [
          {
            "lang": "en",
            "value": "CWE-862"
          }
        ],
        "source": "nvd@nist.gov",
        "type": "Primary"
      }
    ]
  }
}
—
CVSS
cvss
NVD5.9
receipt
Source
NVD
Its words
5.9
Read by
field:cve.metrics.cvssMetricV31[type=Primary].cvssData.baseScore || field:cve.metrics.cvssMetricV31[].cvssData.baseScore
Said since
2026-10-06 11:32 UTC
Last answered
2026-10-06 12:41 UTC
Original
open at the source
2026-10-06 11:32 UTC5.9
2026-10-02 12:00 UTC7.1
What the source handed over
{
  "cve": {
    "affected": [
      {
        "affectedData": [
          {
            "product": "LibreChat",
            "vendor": "danny-avila",
            "versions": [
              {
                "status": "affected",
                "version": ">= 0.8.1-rc2, < 0.8.2-rc2"
              }
            ]
          }
        ],
        "source": "security-advisories@github.com"
      }
    ],
    "configurations": [
      {
        "nodes": [
          {
            "cpeMatch": [
              {
                "criteria": "cpe:2.3:a:librechat:librechat:0.8.1:-:*:*:*:*:*:*",
                "matchCriteriaId": "98BB9E92-2D0E-4975-A966-734F3858551B",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:librechat:librechat:0.8.1:rc1:*:*:*:*:*:*",
                "matchCriteriaId": "8DAB7F45-699A-4383-ABEA-D4374E58EE95",
                "vulnerable": true
              }
            ],
            "negate": false,
            "operator": "OR"
          }
        ]
      }
    ],
    "cveTags": [],
    "descriptions": [
      {
        "lang": "en",
        "value": "LibreChat is a ChatGPT clone with additional features. Version 0.8.1-rc2 does not enforce proper access control for file uploads to an agents file context and file search. An authenticated attacker with access to the agent ID can change the behavior of arbitrary agents by uploading new files to the file context or file search, even if they have no permissions for this agent. This issue is fixed in version 0.8.2-rc2."
      },
      {
        "lang": "es",
        "value": "LibreChat es un clon de ChatGPT con características adicionales. La versión 0.8.1-rc2 no aplica un control de acceso adecuado para la carga de archivos al contexto de archivos de un agente y a la búsqueda de archivos. Un atacante autenticado con acceso al ID del agente puede cambiar el comportamiento de agentes arbitrarios cargando nuevos archivos al contexto de archivos o a la búsqueda de archivos, incluso si no tienen permisos para este agente. Este problema está solucionado en la versión 0.8.2-rc2."
      }
    ],
    "id": "CVE-2025-69220",
    "lastModified": "2026-09-30T23:10:00.237",
    "metrics": {
      "cvssMetricV31": [
        {
          "cvssData": {
            "attackComplexity": "HIGH",
            "attackVector": "NETWORK",
            "availabilityImpact": "LOW",
            "baseScore": 7.1,
            "baseSeverity": "HIGH",
            "confidentialityImpact": "NONE",
            "integrityImpact": "HIGH",
            "privilegesRequired": "LOW",
            "scope": "CHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:N/I:H/A:L",
            "version": "3.1"
          },
          "exploitabilityScore": 1.8,
          "impactScore": 4.7,
          "source": "security-advisories@github.com",
          "type": "Secondary"
        },
        {
          "cvssData": {
            "attackComplexity": "HIGH",
            "attackVector": "NETWORK",
            "availabilityImpact": "NONE",
            "baseScore": 5.9,
            "baseSeverity": "MEDIUM",
            "confidentialityImpact": "NONE",
            "integrityImpact": "HIGH",
            "privilegesRequired": "NONE",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N",
            "version": "3.1"
          },
          "exploitabilityScore": 2.2,
          "impactScore": 3.6,
          "source": "nvd@nist.gov",
          "type": "Primary"
        }
      ],
      "ssvcV203": [
        {
          "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "ssvcData": {
            "id": "CVE-2025-69220",
            "options": [
              {
                "exploitation": "none"
              },
              {
                "automatable": "no"
              },
              {
                "technicalImpact": "partial"
              }
            ],
            "role": "CISA Coordinator",
            "timestamp": "2026-01-07T21:33:29.380614Z",
            "version": "2.0.3"
          }
        }
      ]
    },
    "published": "2026-01-07T21:15:59.547",
    "references": [
      {
        "source": "security-advisories@github.com",
        "tags": [
          "Not Applicable"
        ],
        "url": "https://cwe.mitre.org/data/definitions/284.html"
      },
      {
        "source": "security-advisories@github.com",
        "tags": [
          "Not Applicable"
        ],
        "url": "https://cwe.mitre.org/data/definitions/862.html"
      },
      {
        "source": "security-advisories@github.com",
        "tags": [
          "Patch"
        ],
        "url": "https://github.com/danny-avila/LibreChat/commit/4b9c6ab1cb9de626736de700c7981f38be08d237"
      },
      {
        "source": "security-advisories@github.com",
        "tags": [
          "Release Notes"
        ],
        "url": "https://github.com/danny-avila/LibreChat/releases/tag/v0.8.2-rc2"
      },
      {
        "source": "security-advisories@github.com",
        "tags": [
          "Exploit",
          "Vendor Advisory"
        ],
        "url": "https://github.com/danny-avila/LibreChat/security/advisories/GHSA-xcmf-rpmh-hg59"
      },
      {
        "source": "security-advisories@github.com",
        "tags": [
          "Not Applicable"
        ],
        "url": "https://owasp.org/Top10/A01_2021-Broken_Access_Control"
      },
      {
        "source": "security-advisories@github.com",
        "tags": [
          "Technical Description"
        ],
        "url": "https://owasp.org/www-project-web-security-testing-guide/v42/4-Web_Application_Security_Testing/05-Authorization_Testing/02-Testing_for_Bypassing_Authorization_Schema.html"
      },
      {
        "source": "security-advisories@github.com",
        "tags": [
          "Technical Description"
        ],
        "url": "https://raw.githubusercontent.com/OWASP/ASVS/v5.0.0/5.0/OWASP_Application_Security_Verification_Standard_5.0.0_en.pdf"
      }
    ],
    "sourceIdentifier": "security-advisories@github.com",
    "vulnStatus": "Analyzed",
    "weaknesses": [
      {
        "description": [
          {
            "lang": "en",
            "value": "CWE-284"
          },
          {
            "lang": "en",
            "value": "CWE-862"
          }
        ],
        "source": "security-advisories@github.com",
        "type": "Secondary"
      },
      {
        "description": [
          {
            "lang": "en",
            "value": "CWE-862"
          }
        ],
        "source": "nvd@nist.gov",
        "type": "Primary"
      }
    ]
  }
}
—
CVSS vector
cvss_vector
NVDCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N
receipt
Source
NVD
Its words
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N
Read by
field:cve.metrics.cvssMetricV31[type=Primary].cvssData.vectorString || field:cve.metrics.cvssMetricV31[].cvssData.vectorString
Said since
2026-10-06 12:29 UTC
Last answered
2026-10-06 12:41 UTC
Original
open at the source
2026-10-06 12:29 UTCCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N
2026-10-02 12:00 UTC—
What the source handed over
{
  "cve": {
    "affected": [
      {
        "affectedData": [
          {
            "product": "LibreChat",
            "vendor": "danny-avila",
            "versions": [
              {
                "status": "affected",
                "version": ">= 0.8.1-rc2, < 0.8.2-rc2"
              }
            ]
          }
        ],
        "source": "security-advisories@github.com"
      }
    ],
    "configurations": [
      {
        "nodes": [
          {
            "cpeMatch": [
              {
                "criteria": "cpe:2.3:a:librechat:librechat:0.8.1:-:*:*:*:*:*:*",
                "matchCriteriaId": "98BB9E92-2D0E-4975-A966-734F3858551B",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:librechat:librechat:0.8.1:rc1:*:*:*:*:*:*",
                "matchCriteriaId": "8DAB7F45-699A-4383-ABEA-D4374E58EE95",
                "vulnerable": true
              }
            ],
            "negate": false,
            "operator": "OR"
          }
        ]
      }
    ],
    "cveTags": [],
    "descriptions": [
      {
        "lang": "en",
        "value": "LibreChat is a ChatGPT clone with additional features. Version 0.8.1-rc2 does not enforce proper access control for file uploads to an agents file context and file search. An authenticated attacker with access to the agent ID can change the behavior of arbitrary agents by uploading new files to the file context or file search, even if they have no permissions for this agent. This issue is fixed in version 0.8.2-rc2."
      },
      {
        "lang": "es",
        "value": "LibreChat es un clon de ChatGPT con características adicionales. La versión 0.8.1-rc2 no aplica un control de acceso adecuado para la carga de archivos al contexto de archivos de un agente y a la búsqueda de archivos. Un atacante autenticado con acceso al ID del agente puede cambiar el comportamiento de agentes arbitrarios cargando nuevos archivos al contexto de archivos o a la búsqueda de archivos, incluso si no tienen permisos para este agente. Este problema está solucionado en la versión 0.8.2-rc2."
      }
    ],
    "id": "CVE-2025-69220",
    "lastModified": "2026-09-30T23:10:00.237",
    "metrics": {
      "cvssMetricV31": [
        {
          "cvssData": {
            "attackComplexity": "HIGH",
            "attackVector": "NETWORK",
            "availabilityImpact": "LOW",
            "baseScore": 7.1,
            "baseSeverity": "HIGH",
            "confidentialityImpact": "NONE",
            "integrityImpact": "HIGH",
            "privilegesRequired": "LOW",
            "scope": "CHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:N/I:H/A:L",
            "version": "3.1"
          },
          "exploitabilityScore": 1.8,
          "impactScore": 4.7,
          "source": "security-advisories@github.com",
          "type": "Secondary"
        },
        {
          "cvssData": {
            "attackComplexity": "HIGH",
            "attackVector": "NETWORK",
            "availabilityImpact": "NONE",
            "baseScore": 5.9,
            "baseSeverity": "MEDIUM",
            "confidentialityImpact": "NONE",
            "integrityImpact": "HIGH",
            "privilegesRequired": "NONE",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N",
            "version": "3.1"
          },
          "exploitabilityScore": 2.2,
          "impactScore": 3.6,
          "source": "nvd@nist.gov",
          "type": "Primary"
        }
      ],
      "ssvcV203": [
        {
          "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "ssvcData": {
            "id": "CVE-2025-69220",
            "options": [
              {
                "exploitation": "none"
              },
              {
                "automatable": "no"
              },
              {
                "technicalImpact": "partial"
              }
            ],
            "role": "CISA Coordinator",
            "timestamp": "2026-01-07T21:33:29.380614Z",
            "version": "2.0.3"
          }
        }
      ]
    },
    "published": "2026-01-07T21:15:59.547",
    "references": [
      {
        "source": "security-advisories@github.com",
        "tags": [
          "Not Applicable"
        ],
        "url": "https://cwe.mitre.org/data/definitions/284.html"
      },
      {
        "source": "security-advisories@github.com",
        "tags": [
          "Not Applicable"
        ],
        "url": "https://cwe.mitre.org/data/definitions/862.html"
      },
      {
        "source": "security-advisories@github.com",
        "tags": [
          "Patch"
        ],
        "url": "https://github.com/danny-avila/LibreChat/commit/4b9c6ab1cb9de626736de700c7981f38be08d237"
      },
      {
        "source": "security-advisories@github.com",
        "tags": [
          "Release Notes"
        ],
        "url": "https://github.com/danny-avila/LibreChat/releases/tag/v0.8.2-rc2"
      },
      {
        "source": "security-advisories@github.com",
        "tags": [
          "Exploit",
          "Vendor Advisory"
        ],
        "url": "https://github.com/danny-avila/LibreChat/security/advisories/GHSA-xcmf-rpmh-hg59"
      },
      {
        "source": "security-advisories@github.com",
        "tags": [
          "Not Applicable"
        ],
        "url": "https://owasp.org/Top10/A01_2021-Broken_Access_Control"
      },
      {
        "source": "security-advisories@github.com",
        "tags": [
          "Technical Description"
        ],
        "url": "https://owasp.org/www-project-web-security-testing-guide/v42/4-Web_Application_Security_Testing/05-Authorization_Testing/02-Testing_for_Bypassing_Authorization_Schema.html"
      },
      {
        "source": "security-advisories@github.com",
        "tags": [
          "Technical Description"
        ],
        "url": "https://raw.githubusercontent.com/OWASP/ASVS/v5.0.0/5.0/OWASP_Application_Security_Verification_Standard_5.0.0_en.pdf"
      }
    ],
    "sourceIdentifier": "security-advisories@github.com",
    "vulnStatus": "Analyzed",
    "weaknesses": [
      {
        "description": [
          {
            "lang": "en",
            "value": "CWE-284"
          },
          {
            "lang": "en",
            "value": "CWE-862"
          }
        ],
        "source": "security-advisories@github.com",
        "type": "Secondary"
      },
      {
        "description": [
          {
            "lang": "en",
            "value": "CWE-862"
          }
        ],
        "source": "nvd@nist.gov",
        "type": "Primary"
      }
    ]
  }
}
—
CWE
cwe
NVDCWE-284, CWE-862
receipt
Source
NVD
Its words
CWE-284, CWE-862
Read by
field:cve.weaknesses[].description[].value
Said since
2026-10-06 12:29 UTC
Last answered
2026-10-06 12:41 UTC
Original
open at the source
2026-10-06 12:29 UTCCWE-284, CWE-862
2026-10-02 12:00 UTC—
What the source handed over
{
  "cve": {
    "affected": [
      {
        "affectedData": [
          {
            "product": "LibreChat",
            "vendor": "danny-avila",
            "versions": [
              {
                "status": "affected",
                "version": ">= 0.8.1-rc2, < 0.8.2-rc2"
              }
            ]
          }
        ],
        "source": "security-advisories@github.com"
      }
    ],
    "configurations": [
      {
        "nodes": [
          {
            "cpeMatch": [
              {
                "criteria": "cpe:2.3:a:librechat:librechat:0.8.1:-:*:*:*:*:*:*",
                "matchCriteriaId": "98BB9E92-2D0E-4975-A966-734F3858551B",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:librechat:librechat:0.8.1:rc1:*:*:*:*:*:*",
                "matchCriteriaId": "8DAB7F45-699A-4383-ABEA-D4374E58EE95",
                "vulnerable": true
              }
            ],
            "negate": false,
            "operator": "OR"
          }
        ]
      }
    ],
    "cveTags": [],
    "descriptions": [
      {
        "lang": "en",
        "value": "LibreChat is a ChatGPT clone with additional features. Version 0.8.1-rc2 does not enforce proper access control for file uploads to an agents file context and file search. An authenticated attacker with access to the agent ID can change the behavior of arbitrary agents by uploading new files to the file context or file search, even if they have no permissions for this agent. This issue is fixed in version 0.8.2-rc2."
      },
      {
        "lang": "es",
        "value": "LibreChat es un clon de ChatGPT con características adicionales. La versión 0.8.1-rc2 no aplica un control de acceso adecuado para la carga de archivos al contexto de archivos de un agente y a la búsqueda de archivos. Un atacante autenticado con acceso al ID del agente puede cambiar el comportamiento de agentes arbitrarios cargando nuevos archivos al contexto de archivos o a la búsqueda de archivos, incluso si no tienen permisos para este agente. Este problema está solucionado en la versión 0.8.2-rc2."
      }
    ],
    "id": "CVE-2025-69220",
    "lastModified": "2026-09-30T23:10:00.237",
    "metrics": {
      "cvssMetricV31": [
        {
          "cvssData": {
            "attackComplexity": "HIGH",
            "attackVector": "NETWORK",
            "availabilityImpact": "LOW",
            "baseScore": 7.1,
            "baseSeverity": "HIGH",
            "confidentialityImpact": "NONE",
            "integrityImpact": "HIGH",
            "privilegesRequired": "LOW",
            "scope": "CHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:N/I:H/A:L",
            "version": "3.1"
          },
          "exploitabilityScore": 1.8,
          "impactScore": 4.7,
          "source": "security-advisories@github.com",
          "type": "Secondary"
        },
        {
          "cvssData": {
            "attackComplexity": "HIGH",
            "attackVector": "NETWORK",
            "availabilityImpact": "NONE",
            "baseScore": 5.9,
            "baseSeverity": "MEDIUM",
            "confidentialityImpact": "NONE",
            "integrityImpact": "HIGH",
            "privilegesRequired": "NONE",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N",
            "version": "3.1"
          },
          "exploitabilityScore": 2.2,
          "impactScore": 3.6,
          "source": "nvd@nist.gov",
          "type": "Primary"
        }
      ],
      "ssvcV203": [
        {
          "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "ssvcData": {
            "id": "CVE-2025-69220",
            "options": [
              {
                "exploitation": "none"
              },
              {
                "automatable": "no"
              },
              {
                "technicalImpact": "partial"
              }
            ],
            "role": "CISA Coordinator",
            "timestamp": "2026-01-07T21:33:29.380614Z",
            "version": "2.0.3"
          }
        }
      ]
    },
    "published": "2026-01-07T21:15:59.547",
    "references": [
      {
        "source": "security-advisories@github.com",
        "tags": [
          "Not Applicable"
        ],
        "url": "https://cwe.mitre.org/data/definitions/284.html"
      },
      {
        "source": "security-advisories@github.com",
        "tags": [
          "Not Applicable"
        ],
        "url": "https://cwe.mitre.org/data/definitions/862.html"
      },
      {
        "source": "security-advisories@github.com",
        "tags": [
          "Patch"
        ],
        "url": "https://github.com/danny-avila/LibreChat/commit/4b9c6ab1cb9de626736de700c7981f38be08d237"
      },
      {
        "source": "security-advisories@github.com",
        "tags": [
          "Release Notes"
        ],
        "url": "https://github.com/danny-avila/LibreChat/releases/tag/v0.8.2-rc2"
      },
      {
        "source": "security-advisories@github.com",
        "tags": [
          "Exploit",
          "Vendor Advisory"
        ],
        "url": "https://github.com/danny-avila/LibreChat/security/advisories/GHSA-xcmf-rpmh-hg59"
      },
      {
        "source": "security-advisories@github.com",
        "tags": [
          "Not Applicable"
        ],
        "url": "https://owasp.org/Top10/A01_2021-Broken_Access_Control"
      },
      {
        "source": "security-advisories@github.com",
        "tags": [
          "Technical Description"
        ],
        "url": "https://owasp.org/www-project-web-security-testing-guide/v42/4-Web_Application_Security_Testing/05-Authorization_Testing/02-Testing_for_Bypassing_Authorization_Schema.html"
      },
      {
        "source": "security-advisories@github.com",
        "tags": [
          "Technical Description"
        ],
        "url": "https://raw.githubusercontent.com/OWASP/ASVS/v5.0.0/5.0/OWASP_Application_Security_Verification_Standard_5.0.0_en.pdf"
      }
    ],
    "sourceIdentifier": "security-advisories@github.com",
    "vulnStatus": "Analyzed",
    "weaknesses": [
      {
        "description": [
          {
            "lang": "en",
            "value": "CWE-284"
          },
          {
            "lang": "en",
            "value": "CWE-862"
          }
        ],
        "source": "security-advisories@github.com",
        "type": "Secondary"
      },
      {
        "description": [
          {
            "lang": "en",
            "value": "CWE-862"
          }
        ],
        "source": "nvd@nist.gov",
        "type": "Primary"
      }
    ]
  }
}
—
Exploitation
exploitation
NVDnone
No evidence of exploitation, and no public proof of concept.
receipt
Source
NVD
Its words
none
Read by
field:cve.metrics.ssvcV203[].ssvcData.options[].exploitation
Said since
2026-10-06 12:29 UTC
Last answered
2026-10-06 12:41 UTC
Original
open at the source
2026-10-06 12:29 UTCnone
2026-10-02 12:00 UTC—
What the source handed over
{
  "cve": {
    "affected": [
      {
        "affectedData": [
          {
            "product": "LibreChat",
            "vendor": "danny-avila",
            "versions": [
              {
                "status": "affected",
                "version": ">= 0.8.1-rc2, < 0.8.2-rc2"
              }
            ]
          }
        ],
        "source": "security-advisories@github.com"
      }
    ],
    "configurations": [
      {
        "nodes": [
          {
            "cpeMatch": [
              {
                "criteria": "cpe:2.3:a:librechat:librechat:0.8.1:-:*:*:*:*:*:*",
                "matchCriteriaId": "98BB9E92-2D0E-4975-A966-734F3858551B",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:librechat:librechat:0.8.1:rc1:*:*:*:*:*:*",
                "matchCriteriaId": "8DAB7F45-699A-4383-ABEA-D4374E58EE95",
                "vulnerable": true
              }
            ],
            "negate": false,
            "operator": "OR"
          }
        ]
      }
    ],
    "cveTags": [],
    "descriptions": [
      {
        "lang": "en",
        "value": "LibreChat is a ChatGPT clone with additional features. Version 0.8.1-rc2 does not enforce proper access control for file uploads to an agents file context and file search. An authenticated attacker with access to the agent ID can change the behavior of arbitrary agents by uploading new files to the file context or file search, even if they have no permissions for this agent. This issue is fixed in version 0.8.2-rc2."
      },
      {
        "lang": "es",
        "value": "LibreChat es un clon de ChatGPT con características adicionales. La versión 0.8.1-rc2 no aplica un control de acceso adecuado para la carga de archivos al contexto de archivos de un agente y a la búsqueda de archivos. Un atacante autenticado con acceso al ID del agente puede cambiar el comportamiento de agentes arbitrarios cargando nuevos archivos al contexto de archivos o a la búsqueda de archivos, incluso si no tienen permisos para este agente. Este problema está solucionado en la versión 0.8.2-rc2."
      }
    ],
    "id": "CVE-2025-69220",
    "lastModified": "2026-09-30T23:10:00.237",
    "metrics": {
      "cvssMetricV31": [
        {
          "cvssData": {
            "attackComplexity": "HIGH",
            "attackVector": "NETWORK",
            "availabilityImpact": "LOW",
            "baseScore": 7.1,
            "baseSeverity": "HIGH",
            "confidentialityImpact": "NONE",
            "integrityImpact": "HIGH",
            "privilegesRequired": "LOW",
            "scope": "CHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:N/I:H/A:L",
            "version": "3.1"
          },
          "exploitabilityScore": 1.8,
          "impactScore": 4.7,
          "source": "security-advisories@github.com",
          "type": "Secondary"
        },
        {
          "cvssData": {
            "attackComplexity": "HIGH",
            "attackVector": "NETWORK",
            "availabilityImpact": "NONE",
            "baseScore": 5.9,
            "baseSeverity": "MEDIUM",
            "confidentialityImpact": "NONE",
            "integrityImpact": "HIGH",
            "privilegesRequired": "NONE",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N",
            "version": "3.1"
          },
          "exploitabilityScore": 2.2,
          "impactScore": 3.6,
          "source": "nvd@nist.gov",
          "type": "Primary"
        }
      ],
      "ssvcV203": [
        {
          "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "ssvcData": {
            "id": "CVE-2025-69220",
            "options": [
              {
                "exploitation": "none"
              },
              {
                "automatable": "no"
              },
              {
                "technicalImpact": "partial"
              }
            ],
            "role": "CISA Coordinator",
            "timestamp": "2026-01-07T21:33:29.380614Z",
            "version": "2.0.3"
          }
        }
      ]
    },
    "published": "2026-01-07T21:15:59.547",
    "references": [
      {
        "source": "security-advisories@github.com",
        "tags": [
          "Not Applicable"
        ],
        "url": "https://cwe.mitre.org/data/definitions/284.html"
      },
      {
        "source": "security-advisories@github.com",
        "tags": [
          "Not Applicable"
        ],
        "url": "https://cwe.mitre.org/data/definitions/862.html"
      },
      {
        "source": "security-advisories@github.com",
        "tags": [
          "Patch"
        ],
        "url": "https://github.com/danny-avila/LibreChat/commit/4b9c6ab1cb9de626736de700c7981f38be08d237"
      },
      {
        "source": "security-advisories@github.com",
        "tags": [
          "Release Notes"
        ],
        "url": "https://github.com/danny-avila/LibreChat/releases/tag/v0.8.2-rc2"
      },
      {
        "source": "security-advisories@github.com",
        "tags": [
          "Exploit",
          "Vendor Advisory"
        ],
        "url": "https://github.com/danny-avila/LibreChat/security/advisories/GHSA-xcmf-rpmh-hg59"
      },
      {
        "source": "security-advisories@github.com",
        "tags": [
          "Not Applicable"
        ],
        "url": "https://owasp.org/Top10/A01_2021-Broken_Access_Control"
      },
      {
        "source": "security-advisories@github.com",
        "tags": [
          "Technical Description"
        ],
        "url": "https://owasp.org/www-project-web-security-testing-guide/v42/4-Web_Application_Security_Testing/05-Authorization_Testing/02-Testing_for_Bypassing_Authorization_Schema.html"
      },
      {
        "source": "security-advisories@github.com",
        "tags": [
          "Technical Description"
        ],
        "url": "https://raw.githubusercontent.com/OWASP/ASVS/v5.0.0/5.0/OWASP_Application_Security_Verification_Standard_5.0.0_en.pdf"
      }
    ],
    "sourceIdentifier": "security-advisories@github.com",
    "vulnStatus": "Analyzed",
    "weaknesses": [
      {
        "description": [
          {
            "lang": "en",
            "value": "CWE-284"
          },
          {
            "lang": "en",
            "value": "CWE-862"
          }
        ],
        "source": "security-advisories@github.com",
        "type": "Secondary"
      },
      {
        "description": [
          {
            "lang": "en",
            "value": "CWE-862"
          }
        ],
        "source": "nvd@nist.gov",
        "type": "Primary"
      }
    ]
  }
}
—
Product
product
NVDLibreChat
receipt
Source
NVD
Its words
LibreChat
Read by
field:cve.affected[].affectedData[].product
Said since
2026-10-02 12:00 UTC
Last answered
2026-10-06 12:41 UTC
Original
open at the source
What the source handed over
{
  "cve": {
    "affected": [
      {
        "affectedData": [
          {
            "product": "LibreChat",
            "vendor": "danny-avila",
            "versions": [
              {
                "status": "affected",
                "version": ">= 0.8.1-rc2, < 0.8.2-rc2"
              }
            ]
          }
        ],
        "source": "security-advisories@github.com"
      }
    ],
    "configurations": [
      {
        "nodes": [
          {
            "cpeMatch": [
              {
                "criteria": "cpe:2.3:a:librechat:librechat:0.8.1:-:*:*:*:*:*:*",
                "matchCriteriaId": "98BB9E92-2D0E-4975-A966-734F3858551B",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:librechat:librechat:0.8.1:rc1:*:*:*:*:*:*",
                "matchCriteriaId": "8DAB7F45-699A-4383-ABEA-D4374E58EE95",
                "vulnerable": true
              }
            ],
            "negate": false,
            "operator": "OR"
          }
        ]
      }
    ],
    "cveTags": [],
    "descriptions": [
      {
        "lang": "en",
        "value": "LibreChat is a ChatGPT clone with additional features. Version 0.8.1-rc2 does not enforce proper access control for file uploads to an agents file context and file search. An authenticated attacker with access to the agent ID can change the behavior of arbitrary agents by uploading new files to the file context or file search, even if they have no permissions for this agent. This issue is fixed in version 0.8.2-rc2."
      },
      {
        "lang": "es",
        "value": "LibreChat es un clon de ChatGPT con características adicionales. La versión 0.8.1-rc2 no aplica un control de acceso adecuado para la carga de archivos al contexto de archivos de un agente y a la búsqueda de archivos. Un atacante autenticado con acceso al ID del agente puede cambiar el comportamiento de agentes arbitrarios cargando nuevos archivos al contexto de archivos o a la búsqueda de archivos, incluso si no tienen permisos para este agente. Este problema está solucionado en la versión 0.8.2-rc2."
      }
    ],
    "id": "CVE-2025-69220",
    "lastModified": "2026-09-30T23:10:00.237",
    "metrics": {
      "cvssMetricV31": [
        {
          "cvssData": {
            "attackComplexity": "HIGH",
            "attackVector": "NETWORK",
            "availabilityImpact": "LOW",
            "baseScore": 7.1,
            "baseSeverity": "HIGH",
            "confidentialityImpact": "NONE",
            "integrityImpact": "HIGH",
            "privilegesRequired": "LOW",
            "scope": "CHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:N/I:H/A:L",
            "version": "3.1"
          },
          "exploitabilityScore": 1.8,
          "impactScore": 4.7,
          "source": "security-advisories@github.com",
          "type": "Secondary"
        },
        {
          "cvssData": {
            "attackComplexity": "HIGH",
            "attackVector": "NETWORK",
            "availabilityImpact": "NONE",
            "baseScore": 5.9,
            "baseSeverity": "MEDIUM",
            "confidentialityImpact": "NONE",
            "integrityImpact": "HIGH",
            "privilegesRequired": "NONE",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N",
            "version": "3.1"
          },
          "exploitabilityScore": 2.2,
          "impactScore": 3.6,
          "source": "nvd@nist.gov",
          "type": "Primary"
        }
      ],
      "ssvcV203": [
        {
          "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "ssvcData": {
            "id": "CVE-2025-69220",
            "options": [
              {
                "exploitation": "none"
              },
              {
                "automatable": "no"
              },
              {
                "technicalImpact": "partial"
              }
            ],
            "role": "CISA Coordinator",
            "timestamp": "2026-01-07T21:33:29.380614Z",
            "version": "2.0.3"
          }
        }
      ]
    },
    "published": "2026-01-07T21:15:59.547",
    "references": [
      {
        "source": "security-advisories@github.com",
        "tags": [
          "Not Applicable"
        ],
        "url": "https://cwe.mitre.org/data/definitions/284.html"
      },
      {
        "source": "security-advisories@github.com",
        "tags": [
          "Not Applicable"
        ],
        "url": "https://cwe.mitre.org/data/definitions/862.html"
      },
      {
        "source": "security-advisories@github.com",
        "tags": [
          "Patch"
        ],
        "url": "https://github.com/danny-avila/LibreChat/commit/4b9c6ab1cb9de626736de700c7981f38be08d237"
      },
      {
        "source": "security-advisories@github.com",
        "tags": [
          "Release Notes"
        ],
        "url": "https://github.com/danny-avila/LibreChat/releases/tag/v0.8.2-rc2"
      },
      {
        "source": "security-advisories@github.com",
        "tags": [
          "Exploit",
          "Vendor Advisory"
        ],
        "url": "https://github.com/danny-avila/LibreChat/security/advisories/GHSA-xcmf-rpmh-hg59"
      },
      {
        "source": "security-advisories@github.com",
        "tags": [
          "Not Applicable"
        ],
        "url": "https://owasp.org/Top10/A01_2021-Broken_Access_Control"
      },
      {
        "source": "security-advisories@github.com",
        "tags": [
          "Technical Description"
        ],
        "url": "https://owasp.org/www-project-web-security-testing-guide/v42/4-Web_Application_Security_Testing/05-Authorization_Testing/02-Testing_for_Bypassing_Authorization_Schema.html"
      },
      {
        "source": "security-advisories@github.com",
        "tags": [
          "Technical Description"
        ],
        "url": "https://raw.githubusercontent.com/OWASP/ASVS/v5.0.0/5.0/OWASP_Application_Security_Verification_Standard_5.0.0_en.pdf"
      }
    ],
    "sourceIdentifier": "security-advisories@github.com",
    "vulnStatus": "Analyzed",
    "weaknesses": [
      {
        "description": [
          {
            "lang": "en",
            "value": "CWE-284"
          },
          {
            "lang": "en",
            "value": "CWE-862"
          }
        ],
        "source": "security-advisories@github.com",
        "type": "Secondary"
      },
      {
        "description": [
          {
            "lang": "en",
            "value": "CWE-862"
          }
        ],
        "source": "nvd@nist.gov",
        "type": "Primary"
      }
    ]
  }
}
—
Severity
severity
NVDMEDIUM
From 4.0 to 6.9.
receipt
Source
NVD
Its words
MEDIUM
Read by
field:cve.metrics.cvssMetricV31[type=Primary].cvssData.baseSeverity || field:cve.metrics.cvssMetricV31[].cvssData.baseSeverity
Said since
2026-10-06 12:29 UTC
Last answered
2026-10-06 12:41 UTC
Original
open at the source
2026-10-06 12:29 UTCMEDIUM
2026-10-02 12:00 UTC—
What the source handed over
{
  "cve": {
    "affected": [
      {
        "affectedData": [
          {
            "product": "LibreChat",
            "vendor": "danny-avila",
            "versions": [
              {
                "status": "affected",
                "version": ">= 0.8.1-rc2, < 0.8.2-rc2"
              }
            ]
          }
        ],
        "source": "security-advisories@github.com"
      }
    ],
    "configurations": [
      {
        "nodes": [
          {
            "cpeMatch": [
              {
                "criteria": "cpe:2.3:a:librechat:librechat:0.8.1:-:*:*:*:*:*:*",
                "matchCriteriaId": "98BB9E92-2D0E-4975-A966-734F3858551B",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:librechat:librechat:0.8.1:rc1:*:*:*:*:*:*",
                "matchCriteriaId": "8DAB7F45-699A-4383-ABEA-D4374E58EE95",
                "vulnerable": true
              }
            ],
            "negate": false,
            "operator": "OR"
          }
        ]
      }
    ],
    "cveTags": [],
    "descriptions": [
      {
        "lang": "en",
        "value": "LibreChat is a ChatGPT clone with additional features. Version 0.8.1-rc2 does not enforce proper access control for file uploads to an agents file context and file search. An authenticated attacker with access to the agent ID can change the behavior of arbitrary agents by uploading new files to the file context or file search, even if they have no permissions for this agent. This issue is fixed in version 0.8.2-rc2."
      },
      {
        "lang": "es",
        "value": "LibreChat es un clon de ChatGPT con características adicionales. La versión 0.8.1-rc2 no aplica un control de acceso adecuado para la carga de archivos al contexto de archivos de un agente y a la búsqueda de archivos. Un atacante autenticado con acceso al ID del agente puede cambiar el comportamiento de agentes arbitrarios cargando nuevos archivos al contexto de archivos o a la búsqueda de archivos, incluso si no tienen permisos para este agente. Este problema está solucionado en la versión 0.8.2-rc2."
      }
    ],
    "id": "CVE-2025-69220",
    "lastModified": "2026-09-30T23:10:00.237",
    "metrics": {
      "cvssMetricV31": [
        {
          "cvssData": {
            "attackComplexity": "HIGH",
            "attackVector": "NETWORK",
            "availabilityImpact": "LOW",
            "baseScore": 7.1,
            "baseSeverity": "HIGH",
            "confidentialityImpact": "NONE",
            "integrityImpact": "HIGH",
            "privilegesRequired": "LOW",
            "scope": "CHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:N/I:H/A:L",
            "version": "3.1"
          },
          "exploitabilityScore": 1.8,
          "impactScore": 4.7,
          "source": "security-advisories@github.com",
          "type": "Secondary"
        },
        {
          "cvssData": {
            "attackComplexity": "HIGH",
            "attackVector": "NETWORK",
            "availabilityImpact": "NONE",
            "baseScore": 5.9,
            "baseSeverity": "MEDIUM",
            "confidentialityImpact": "NONE",
            "integrityImpact": "HIGH",
            "privilegesRequired": "NONE",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N",
            "version": "3.1"
          },
          "exploitabilityScore": 2.2,
          "impactScore": 3.6,
          "source": "nvd@nist.gov",
          "type": "Primary"
        }
      ],
      "ssvcV203": [
        {
          "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "ssvcData": {
            "id": "CVE-2025-69220",
            "options": [
              {
                "exploitation": "none"
              },
              {
                "automatable": "no"
              },
              {
                "technicalImpact": "partial"
              }
            ],
            "role": "CISA Coordinator",
            "timestamp": "2026-01-07T21:33:29.380614Z",
            "version": "2.0.3"
          }
        }
      ]
    },
    "published": "2026-01-07T21:15:59.547",
    "references": [
      {
        "source": "security-advisories@github.com",
        "tags": [
          "Not Applicable"
        ],
        "url": "https://cwe.mitre.org/data/definitions/284.html"
      },
      {
        "source": "security-advisories@github.com",
        "tags": [
          "Not Applicable"
        ],
        "url": "https://cwe.mitre.org/data/definitions/862.html"
      },
      {
        "source": "security-advisories@github.com",
        "tags": [
          "Patch"
        ],
        "url": "https://github.com/danny-avila/LibreChat/commit/4b9c6ab1cb9de626736de700c7981f38be08d237"
      },
      {
        "source": "security-advisories@github.com",
        "tags": [
          "Release Notes"
        ],
        "url": "https://github.com/danny-avila/LibreChat/releases/tag/v0.8.2-rc2"
      },
      {
        "source": "security-advisories@github.com",
        "tags": [
          "Exploit",
          "Vendor Advisory"
        ],
        "url": "https://github.com/danny-avila/LibreChat/security/advisories/GHSA-xcmf-rpmh-hg59"
      },
      {
        "source": "security-advisories@github.com",
        "tags": [
          "Not Applicable"
        ],
        "url": "https://owasp.org/Top10/A01_2021-Broken_Access_Control"
      },
      {
        "source": "security-advisories@github.com",
        "tags": [
          "Technical Description"
        ],
        "url": "https://owasp.org/www-project-web-security-testing-guide/v42/4-Web_Application_Security_Testing/05-Authorization_Testing/02-Testing_for_Bypassing_Authorization_Schema.html"
      },
      {
        "source": "security-advisories@github.com",
        "tags": [
          "Technical Description"
        ],
        "url": "https://raw.githubusercontent.com/OWASP/ASVS/v5.0.0/5.0/OWASP_Application_Security_Verification_Standard_5.0.0_en.pdf"
      }
    ],
    "sourceIdentifier": "security-advisories@github.com",
    "vulnStatus": "Analyzed",
    "weaknesses": [
      {
        "description": [
          {
            "lang": "en",
            "value": "CWE-284"
          },
          {
            "lang": "en",
            "value": "CWE-862"
          }
        ],
        "source": "security-advisories@github.com",
        "type": "Secondary"
      },
      {
        "description": [
          {
            "lang": "en",
            "value": "CWE-862"
          }
        ],
        "source": "nvd@nist.gov",
        "type": "Primary"
      }
    ]
  }
}
medium
Status
status
NVDAnalyzed
receipt
Source
NVD
Its words
Analyzed
Read by
field:cve.vulnStatus
Said since
2026-10-02 12:00 UTC
Last answered
2026-10-06 12:41 UTC
Original
open at the source
What the source handed over
{
  "cve": {
    "affected": [
      {
        "affectedData": [
          {
            "product": "LibreChat",
            "vendor": "danny-avila",
            "versions": [
              {
                "status": "affected",
                "version": ">= 0.8.1-rc2, < 0.8.2-rc2"
              }
            ]
          }
        ],
        "source": "security-advisories@github.com"
      }
    ],
    "configurations": [
      {
        "nodes": [
          {
            "cpeMatch": [
              {
                "criteria": "cpe:2.3:a:librechat:librechat:0.8.1:-:*:*:*:*:*:*",
                "matchCriteriaId": "98BB9E92-2D0E-4975-A966-734F3858551B",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:librechat:librechat:0.8.1:rc1:*:*:*:*:*:*",
                "matchCriteriaId": "8DAB7F45-699A-4383-ABEA-D4374E58EE95",
                "vulnerable": true
              }
            ],
            "negate": false,
            "operator": "OR"
          }
        ]
      }
    ],
    "cveTags": [],
    "descriptions": [
      {
        "lang": "en",
        "value": "LibreChat is a ChatGPT clone with additional features. Version 0.8.1-rc2 does not enforce proper access control for file uploads to an agents file context and file search. An authenticated attacker with access to the agent ID can change the behavior of arbitrary agents by uploading new files to the file context or file search, even if they have no permissions for this agent. This issue is fixed in version 0.8.2-rc2."
      },
      {
        "lang": "es",
        "value": "LibreChat es un clon de ChatGPT con características adicionales. La versión 0.8.1-rc2 no aplica un control de acceso adecuado para la carga de archivos al contexto de archivos de un agente y a la búsqueda de archivos. Un atacante autenticado con acceso al ID del agente puede cambiar el comportamiento de agentes arbitrarios cargando nuevos archivos al contexto de archivos o a la búsqueda de archivos, incluso si no tienen permisos para este agente. Este problema está solucionado en la versión 0.8.2-rc2."
      }
    ],
    "id": "CVE-2025-69220",
    "lastModified": "2026-09-30T23:10:00.237",
    "metrics": {
      "cvssMetricV31": [
        {
          "cvssData": {
            "attackComplexity": "HIGH",
            "attackVector": "NETWORK",
            "availabilityImpact": "LOW",
            "baseScore": 7.1,
            "baseSeverity": "HIGH",
            "confidentialityImpact": "NONE",
            "integrityImpact": "HIGH",
            "privilegesRequired": "LOW",
            "scope": "CHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:N/I:H/A:L",
            "version": "3.1"
          },
          "exploitabilityScore": 1.8,
          "impactScore": 4.7,
          "source": "security-advisories@github.com",
          "type": "Secondary"
        },
        {
          "cvssData": {
            "attackComplexity": "HIGH",
            "attackVector": "NETWORK",
            "availabilityImpact": "NONE",
            "baseScore": 5.9,
            "baseSeverity": "MEDIUM",
            "confidentialityImpact": "NONE",
            "integrityImpact": "HIGH",
            "privilegesRequired": "NONE",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N",
            "version": "3.1"
          },
          "exploitabilityScore": 2.2,
          "impactScore": 3.6,
          "source": "nvd@nist.gov",
          "type": "Primary"
        }
      ],
      "ssvcV203": [
        {
          "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "ssvcData": {
            "id": "CVE-2025-69220",
            "options": [
              {
                "exploitation": "none"
              },
              {
                "automatable": "no"
              },
              {
                "technicalImpact": "partial"
              }
            ],
            "role": "CISA Coordinator",
            "timestamp": "2026-01-07T21:33:29.380614Z",
            "version": "2.0.3"
          }
        }
      ]
    },
    "published": "2026-01-07T21:15:59.547",
    "references": [
      {
        "source": "security-advisories@github.com",
        "tags": [
          "Not Applicable"
        ],
        "url": "https://cwe.mitre.org/data/definitions/284.html"
      },
      {
        "source": "security-advisories@github.com",
        "tags": [
          "Not Applicable"
        ],
        "url": "https://cwe.mitre.org/data/definitions/862.html"
      },
      {
        "source": "security-advisories@github.com",
        "tags": [
          "Patch"
        ],
        "url": "https://github.com/danny-avila/LibreChat/commit/4b9c6ab1cb9de626736de700c7981f38be08d237"
      },
      {
        "source": "security-advisories@github.com",
        "tags": [
          "Release Notes"
        ],
        "url": "https://github.com/danny-avila/LibreChat/releases/tag/v0.8.2-rc2"
      },
      {
        "source": "security-advisories@github.com",
        "tags": [
          "Exploit",
          "Vendor Advisory"
        ],
        "url": "https://github.com/danny-avila/LibreChat/security/advisories/GHSA-xcmf-rpmh-hg59"
      },
      {
        "source": "security-advisories@github.com",
        "tags": [
          "Not Applicable"
        ],
        "url": "https://owasp.org/Top10/A01_2021-Broken_Access_Control"
      },
      {
        "source": "security-advisories@github.com",
        "tags": [
          "Technical Description"
        ],
        "url": "https://owasp.org/www-project-web-security-testing-guide/v42/4-Web_Application_Security_Testing/05-Authorization_Testing/02-Testing_for_Bypassing_Authorization_Schema.html"
      },
      {
        "source": "security-advisories@github.com",
        "tags": [
          "Technical Description"
        ],
        "url": "https://raw.githubusercontent.com/OWASP/ASVS/v5.0.0/5.0/OWASP_Application_Security_Verification_Standard_5.0.0_en.pdf"
      }
    ],
    "sourceIdentifier": "security-advisories@github.com",
    "vulnStatus": "Analyzed",
    "weaknesses": [
      {
        "description": [
          {
            "lang": "en",
            "value": "CWE-284"
          },
          {
            "lang": "en",
            "value": "CWE-862"
          }
        ],
        "source": "security-advisories@github.com",
        "type": "Secondary"
      },
      {
        "description": [
          {
            "lang": "en",
            "value": "CWE-862"
          }
        ],
        "source": "nvd@nist.gov",
        "type": "Primary"
      }
    ]
  }
}
—
Technical impact
technical_impact
NVDpartial
The attacker gains limited control, or limited information.
receipt
Source
NVD
Its words
partial
Read by
field:cve.metrics.ssvcV203[].ssvcData.options[].technicalImpact
Said since
2026-10-06 12:29 UTC
Last answered
2026-10-06 12:41 UTC
Original
open at the source
2026-10-06 12:29 UTCpartial
2026-10-02 12:00 UTC—
What the source handed over
{
  "cve": {
    "affected": [
      {
        "affectedData": [
          {
            "product": "LibreChat",
            "vendor": "danny-avila",
            "versions": [
              {
                "status": "affected",
                "version": ">= 0.8.1-rc2, < 0.8.2-rc2"
              }
            ]
          }
        ],
        "source": "security-advisories@github.com"
      }
    ],
    "configurations": [
      {
        "nodes": [
          {
            "cpeMatch": [
              {
                "criteria": "cpe:2.3:a:librechat:librechat:0.8.1:-:*:*:*:*:*:*",
                "matchCriteriaId": "98BB9E92-2D0E-4975-A966-734F3858551B",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:librechat:librechat:0.8.1:rc1:*:*:*:*:*:*",
                "matchCriteriaId": "8DAB7F45-699A-4383-ABEA-D4374E58EE95",
                "vulnerable": true
              }
            ],
            "negate": false,
            "operator": "OR"
          }
        ]
      }
    ],
    "cveTags": [],
    "descriptions": [
      {
        "lang": "en",
        "value": "LibreChat is a ChatGPT clone with additional features. Version 0.8.1-rc2 does not enforce proper access control for file uploads to an agents file context and file search. An authenticated attacker with access to the agent ID can change the behavior of arbitrary agents by uploading new files to the file context or file search, even if they have no permissions for this agent. This issue is fixed in version 0.8.2-rc2."
      },
      {
        "lang": "es",
        "value": "LibreChat es un clon de ChatGPT con características adicionales. La versión 0.8.1-rc2 no aplica un control de acceso adecuado para la carga de archivos al contexto de archivos de un agente y a la búsqueda de archivos. Un atacante autenticado con acceso al ID del agente puede cambiar el comportamiento de agentes arbitrarios cargando nuevos archivos al contexto de archivos o a la búsqueda de archivos, incluso si no tienen permisos para este agente. Este problema está solucionado en la versión 0.8.2-rc2."
      }
    ],
    "id": "CVE-2025-69220",
    "lastModified": "2026-09-30T23:10:00.237",
    "metrics": {
      "cvssMetricV31": [
        {
          "cvssData": {
            "attackComplexity": "HIGH",
            "attackVector": "NETWORK",
            "availabilityImpact": "LOW",
            "baseScore": 7.1,
            "baseSeverity": "HIGH",
            "confidentialityImpact": "NONE",
            "integrityImpact": "HIGH",
            "privilegesRequired": "LOW",
            "scope": "CHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:N/I:H/A:L",
            "version": "3.1"
          },
          "exploitabilityScore": 1.8,
          "impactScore": 4.7,
          "source": "security-advisories@github.com",
          "type": "Secondary"
        },
        {
          "cvssData": {
            "attackComplexity": "HIGH",
            "attackVector": "NETWORK",
            "availabilityImpact": "NONE",
            "baseScore": 5.9,
            "baseSeverity": "MEDIUM",
            "confidentialityImpact": "NONE",
            "integrityImpact": "HIGH",
            "privilegesRequired": "NONE",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N",
            "version": "3.1"
          },
          "exploitabilityScore": 2.2,
          "impactScore": 3.6,
          "source": "nvd@nist.gov",
          "type": "Primary"
        }
      ],
      "ssvcV203": [
        {
          "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "ssvcData": {
            "id": "CVE-2025-69220",
            "options": [
              {
                "exploitation": "none"
              },
              {
                "automatable": "no"
              },
              {
                "technicalImpact": "partial"
              }
            ],
            "role": "CISA Coordinator",
            "timestamp": "2026-01-07T21:33:29.380614Z",
            "version": "2.0.3"
          }
        }
      ]
    },
    "published": "2026-01-07T21:15:59.547",
    "references": [
      {
        "source": "security-advisories@github.com",
        "tags": [
          "Not Applicable"
        ],
        "url": "https://cwe.mitre.org/data/definitions/284.html"
      },
      {
        "source": "security-advisories@github.com",
        "tags": [
          "Not Applicable"
        ],
        "url": "https://cwe.mitre.org/data/definitions/862.html"
      },
      {
        "source": "security-advisories@github.com",
        "tags": [
          "Patch"
        ],
        "url": "https://github.com/danny-avila/LibreChat/commit/4b9c6ab1cb9de626736de700c7981f38be08d237"
      },
      {
        "source": "security-advisories@github.com",
        "tags": [
          "Release Notes"
        ],
        "url": "https://github.com/danny-avila/LibreChat/releases/tag/v0.8.2-rc2"
      },
      {
        "source": "security-advisories@github.com",
        "tags": [
          "Exploit",
          "Vendor Advisory"
        ],
        "url": "https://github.com/danny-avila/LibreChat/security/advisories/GHSA-xcmf-rpmh-hg59"
      },
      {
        "source": "security-advisories@github.com",
        "tags": [
          "Not Applicable"
        ],
        "url": "https://owasp.org/Top10/A01_2021-Broken_Access_Control"
      },
      {
        "source": "security-advisories@github.com",
        "tags": [
          "Technical Description"
        ],
        "url": "https://owasp.org/www-project-web-security-testing-guide/v42/4-Web_Application_Security_Testing/05-Authorization_Testing/02-Testing_for_Bypassing_Authorization_Schema.html"
      },
      {
        "source": "security-advisories@github.com",
        "tags": [
          "Technical Description"
        ],
        "url": "https://raw.githubusercontent.com/OWASP/ASVS/v5.0.0/5.0/OWASP_Application_Security_Verification_Standard_5.0.0_en.pdf"
      }
    ],
    "sourceIdentifier": "security-advisories@github.com",
    "vulnStatus": "Analyzed",
    "weaknesses": [
      {
        "description": [
          {
            "lang": "en",
            "value": "CWE-284"
          },
          {
            "lang": "en",
            "value": "CWE-862"
          }
        ],
        "source": "security-advisories@github.com",
        "type": "Secondary"
      },
      {
        "description": [
          {
            "lang": "en",
            "value": "CWE-862"
          }
        ],
        "source": "nvd@nist.gov",
        "type": "Primary"
      }
    ]
  }
}
—
Vendor
vendor
NVDdanny-avila
receipt
Source
NVD
Its words
danny-avila
Read by
field:cve.affected[].affectedData[].vendor
Said since
2026-10-02 12:00 UTC
Last answered
2026-10-06 12:41 UTC
Original
open at the source
What the source handed over
{
  "cve": {
    "affected": [
      {
        "affectedData": [
          {
            "product": "LibreChat",
            "vendor": "danny-avila",
            "versions": [
              {
                "status": "affected",
                "version": ">= 0.8.1-rc2, < 0.8.2-rc2"
              }
            ]
          }
        ],
        "source": "security-advisories@github.com"
      }
    ],
    "configurations": [
      {
        "nodes": [
          {
            "cpeMatch": [
              {
                "criteria": "cpe:2.3:a:librechat:librechat:0.8.1:-:*:*:*:*:*:*",
                "matchCriteriaId": "98BB9E92-2D0E-4975-A966-734F3858551B",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:librechat:librechat:0.8.1:rc1:*:*:*:*:*:*",
                "matchCriteriaId": "8DAB7F45-699A-4383-ABEA-D4374E58EE95",
                "vulnerable": true
              }
            ],
            "negate": false,
            "operator": "OR"
          }
        ]
      }
    ],
    "cveTags": [],
    "descriptions": [
      {
        "lang": "en",
        "value": "LibreChat is a ChatGPT clone with additional features. Version 0.8.1-rc2 does not enforce proper access control for file uploads to an agents file context and file search. An authenticated attacker with access to the agent ID can change the behavior of arbitrary agents by uploading new files to the file context or file search, even if they have no permissions for this agent. This issue is fixed in version 0.8.2-rc2."
      },
      {
        "lang": "es",
        "value": "LibreChat es un clon de ChatGPT con características adicionales. La versión 0.8.1-rc2 no aplica un control de acceso adecuado para la carga de archivos al contexto de archivos de un agente y a la búsqueda de archivos. Un atacante autenticado con acceso al ID del agente puede cambiar el comportamiento de agentes arbitrarios cargando nuevos archivos al contexto de archivos o a la búsqueda de archivos, incluso si no tienen permisos para este agente. Este problema está solucionado en la versión 0.8.2-rc2."
      }
    ],
    "id": "CVE-2025-69220",
    "lastModified": "2026-09-30T23:10:00.237",
    "metrics": {
      "cvssMetricV31": [
        {
          "cvssData": {
            "attackComplexity": "HIGH",
            "attackVector": "NETWORK",
            "availabilityImpact": "LOW",
            "baseScore": 7.1,
            "baseSeverity": "HIGH",
            "confidentialityImpact": "NONE",
            "integrityImpact": "HIGH",
            "privilegesRequired": "LOW",
            "scope": "CHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:N/I:H/A:L",
            "version": "3.1"
          },
          "exploitabilityScore": 1.8,
          "impactScore": 4.7,
          "source": "security-advisories@github.com",
          "type": "Secondary"
        },
        {
          "cvssData": {
            "attackComplexity": "HIGH",
            "attackVector": "NETWORK",
            "availabilityImpact": "NONE",
            "baseScore": 5.9,
            "baseSeverity": "MEDIUM",
            "confidentialityImpact": "NONE",
            "integrityImpact": "HIGH",
            "privilegesRequired": "NONE",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N",
            "version": "3.1"
          },
          "exploitabilityScore": 2.2,
          "impactScore": 3.6,
          "source": "nvd@nist.gov",
          "type": "Primary"
        }
      ],
      "ssvcV203": [
        {
          "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "ssvcData": {
            "id": "CVE-2025-69220",
            "options": [
              {
                "exploitation": "none"
              },
              {
                "automatable": "no"
              },
              {
                "technicalImpact": "partial"
              }
            ],
            "role": "CISA Coordinator",
            "timestamp": "2026-01-07T21:33:29.380614Z",
            "version": "2.0.3"
          }
        }
      ]
    },
    "published": "2026-01-07T21:15:59.547",
    "references": [
      {
        "source": "security-advisories@github.com",
        "tags": [
          "Not Applicable"
        ],
        "url": "https://cwe.mitre.org/data/definitions/284.html"
      },
      {
        "source": "security-advisories@github.com",
        "tags": [
          "Not Applicable"
        ],
        "url": "https://cwe.mitre.org/data/definitions/862.html"
      },
      {
        "source": "security-advisories@github.com",
        "tags": [
          "Patch"
        ],
        "url": "https://github.com/danny-avila/LibreChat/commit/4b9c6ab1cb9de626736de700c7981f38be08d237"
      },
      {
        "source": "security-advisories@github.com",
        "tags": [
          "Release Notes"
        ],
        "url": "https://github.com/danny-avila/LibreChat/releases/tag/v0.8.2-rc2"
      },
      {
        "source": "security-advisories@github.com",
        "tags": [
          "Exploit",
          "Vendor Advisory"
        ],
        "url": "https://github.com/danny-avila/LibreChat/security/advisories/GHSA-xcmf-rpmh-hg59"
      },
      {
        "source": "security-advisories@github.com",
        "tags": [
          "Not Applicable"
        ],
        "url": "https://owasp.org/Top10/A01_2021-Broken_Access_Control"
      },
      {
        "source": "security-advisories@github.com",
        "tags": [
          "Technical Description"
        ],
        "url": "https://owasp.org/www-project-web-security-testing-guide/v42/4-Web_Application_Security_Testing/05-Authorization_Testing/02-Testing_for_Bypassing_Authorization_Schema.html"
      },
      {
        "source": "security-advisories@github.com",
        "tags": [
          "Technical Description"
        ],
        "url": "https://raw.githubusercontent.com/OWASP/ASVS/v5.0.0/5.0/OWASP_Application_Security_Verification_Standard_5.0.0_en.pdf"
      }
    ],
    "sourceIdentifier": "security-advisories@github.com",
    "vulnStatus": "Analyzed",
    "weaknesses": [
      {
        "description": [
          {
            "lang": "en",
            "value": "CWE-284"
          },
          {
            "lang": "en",
            "value": "CWE-862"
          }
        ],
        "source": "security-advisories@github.com",
        "type": "Secondary"
      },
      {
        "description": [
          {
            "lang": "en",
            "value": "CWE-862"
          }
        ],
        "source": "nvd@nist.gov",
        "type": "Primary"
      }
    ]
  }
}
—
Every claim, by kind

vulnerability

LibreChat is a ChatGPT clone with additional features. Version 0.8.1-rc2 does not enforce proper access control for file uploads to an agents file context and file search. An authenticated attacker with access to the agent ID can change the behavior of arbitrary agents by uploading new files to the file context or file search, even if they have no permissions for this agent. This issue is fixed in version 0.8.2-rc2.
zetlyn/cve-nvd · 2026-01-07
automatable no cvss 5.9 cvss_vector CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N cwe CWE-284, CWE-862 exploitation none product LibreChat severity MEDIUM status Analyzed technical_impact partial vendor danny-avila source