Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1310 CNY

100%

CVE-2026-44654— LibreChat: Shared-agent editor can globally delete owner's file records — breaks owner's other private agents

AI Predicted 6.5 Difficulty: Easy
Get alerts for future matching vulnerabilitiesLog in to subscribe

I. Basic Information for CVE-2026-44654

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
LibreChat: Shared-agent editor can globally delete owner's file records — breaks owner's other private agents
Source: NVD (National Vulnerability Database)
Vulnerability Description
LibreChat is an enhanced ChatGPT clone that supports multiple AI providers. In versions up to and including 0.8.3, a shared-agent editor can delete file records through `DELETE /api/files` that the owner has reused across multiple agents. The deletion removes the file globally — not just from the shared agent — breaking the owner's other private agents that reference the same `file_id`. The private agent retains a stale `file_id` reference that no longer resolves. A shared-agent editor can destroy files that the owner uses across multiple agents. The owner's private agents — which the attacker has no access to — break silently with stale `file_id` references. This is a cross-agent integrity violation: editing access to one agent should not affect another. Version 0.8.4 contains a patch.
Source: NVD (National Vulnerability Database)
CVSS Information
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Type
授权机制不正确
Source: NVD (National Vulnerability Database)

Affected Products

VendorProductAffected VersionsCPESubscribe
danny-avilaLibreChat < 0.8.5 -

II. Public POCs for CVE-2026-44654

#POC DescriptionSource LinkShenlong Link
AI-Generated POCPremium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-44654

登录查看更多情报信息。

Vendor Advisories for CVE-2026-44654 (1)

Same Patch Batch · danny-avila · 2026-06-02 · 4 CVEs total

CVE-2026-326259.6 CRITICALLibreChat Exfiltrates Server Secrets via MCP Server URL Injection
CVE-2026-319427.1 HIGHLibreChat has IDOR in API Keys Management that allows any authenticated user to overwrite
CVE-2026-446536.5 MEDIUMLibreChat Shared MCP Server View Leaks Decrypted Admin Secrets

IV. Related Vulnerabilities

V. Comments for CVE-2026-44654

No comments yet


Leave a comment