Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2025-69222

Опубликовано: 07 янв. 2026
Источник: nvd
CVSS3: 9.1
CVSS3: 8.1
EPSS Низкий

Описание

LibreChat is a ChatGPT clone with additional features. Version 0.8.1-rc2 is prone to a server-side request forgery (SSRF) vulnerability due to missing restrictions of the Actions feature in the default configuration. LibreChat enables users to configure agents with predefined instructions and actions that can interact with remote services via OpenAPI specifications, supporting various HTTP methods, parameters, and authentication methods including custom headers. By default, there are no restrictions on accessible services, which means agents can also access internal components like the RAG API included in the default Docker Compose setup. This issue is fixed in version 0.8.1-rc2.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:librechat:librechat:0.8.1:-:*:*:*:*:*:*
cpe:2.3:a:librechat:librechat:0.8.1:rc1:*:*:*:*:*:*

EPSS

Процентиль: 38%
0.00168
Низкий

9.1 Critical

CVSS3

8.1 High

CVSS3

Дефекты

CWE-918

EPSS

Процентиль: 38%
0.00168
Низкий

9.1 Critical

CVSS3

8.1 High

CVSS3

Дефекты

CWE-918