LibreChat是LibreChat开源的一个免费、高度可定制的统一 AI 对话平台,能够在一个界面中聚合并运行来自任意厂商的大模型。 LibreChat 0.8.1-rc2版本存在安全漏洞,该漏洞源于查询代理权限时访问控制不当,可能导致任意代理权限信息泄露。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| danny-avila | LibreChat | < 0.8.1-rc2 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2025-69222 | 9.1 CRITICAL | LibreChat is vulnerable to Server-Side Request Forgery due to missing restrictions |
| CVE-2025-69220 | 7.1 HIGH | LibreChat has Insufficient Access Control for Agent Files |
No comments yet