Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2025-7104

Опубликовано: 29 сент. 2025
Источник: nvd
CVSS3: 4.3
CVSS3: 7.5
EPSS Низкий

Описание

A mass assignment vulnerability exists in danny-avila/librechat, affecting all versions. This vulnerability allows attackers to manipulate sensitive fields by automatically binding user-provided data to internal object properties or database fields without proper filtering. As a result, any extra fields in the request body are included in agentData and passed to the database layer, allowing overwriting of any field in the schema, such as author, access_level, isCollaborative, and projectIds. Additionally, the Object.Prototype can be polluted due to the use of Object.assign with spread operators.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:librechat:librechat:*:*:*:*:*:*:*:*
Версия до 0.7.9 (исключая)

EPSS

Процентиль: 21%
0.00069
Низкий

4.3 Medium

CVSS3

7.5 High

CVSS3

Дефекты

CWE-915

Связанные уязвимости

CVSS3: 4.3
github
4 месяца назад

A mass assignment vulnerability exists in danny-avila/librechat, affecting all versions. This vulnerability allows attackers to manipulate sensitive fields by automatically binding user-provided data to internal object properties or database fields without proper filtering. As a result, any extra fields in the request body are included in agentData and passed to the database layer, allowing overwriting of any field in the schema, such as author, access_level, isCollaborative, and projectIds. Additionally, the Object.Prototype can be polluted due to the use of Object.assign with spread operators.

EPSS

Процентиль: 21%
0.00069
Низкий

4.3 Medium

CVSS3

7.5 High

CVSS3

Дефекты

CWE-915