Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2026-31944

Опубликовано: 13 мар. 2026
Источник: nvd
CVSS3: 7.6
EPSS Низкий

Описание

LibreChat is a ChatGPT clone with additional features. From 0.8.2 to 0.8.2-rc3, The MCP (Model Context Protocol) OAuth callback endpoint accepts the redirect from the identity provider and stores OAuth tokens for the user who initiated the flow, without verifying that the browser hitting the redirect URL is logged in or that the logged-in user matches the initiator. An attacker can send the authorization URL to a victim; when the victim completes the flow, the victim’s OAuth tokens are stored on the attacker’s LibreChat account, enabling account takeover of the victim’s MCP-linked services (e.g. Atlassian, Outlook). This vulnerability is fixed in 0.8.3-rc1.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:librechat:librechat:0.8.2:-:*:*:*:*:*:*
cpe:2.3:a:librechat:librechat:0.8.2:rc1:*:*:*:*:*:*
cpe:2.3:a:librechat:librechat:0.8.2:rc2:*:*:*:*:*:*
cpe:2.3:a:librechat:librechat:0.8.2:rc3:*:*:*:*:*:*

EPSS

Процентиль: 16%
0.00244
Низкий

7.6 High

CVSS3

Дефекты

CWE-306

Связанные уязвимости

CVSS3: 7.6
fstec
5 месяцев назад

Уязвимость реализации протокола OAuth платформы на базе искуственного интеллекта LibreChat, позволяющая нарушителю получить несанкционированный доступ к защищаемой информации

EPSS

Процентиль: 16%
0.00244
Низкий

7.6 High

CVSS3

Дефекты

CWE-306