Описание
LibreChat is a ChatGPT clone with additional features. From 0.8.2 to 0.8.2-rc3, The MCP (Model Context Protocol) OAuth callback endpoint accepts the redirect from the identity provider and stores OAuth tokens for the user who initiated the flow, without verifying that the browser hitting the redirect URL is logged in or that the logged-in user matches the initiator. An attacker can send the authorization URL to a victim; when the victim completes the flow, the victim’s OAuth tokens are stored on the attacker’s LibreChat account, enabling account takeover of the victim’s MCP-linked services (e.g. Atlassian, Outlook). This vulnerability is fixed in 0.8.3-rc1.
Ссылки
- ExploitVendor Advisory
Уязвимые конфигурации
Одно из
EPSS
7.6 High
CVSS3
Дефекты
Связанные уязвимости
Уязвимость реализации протокола OAuth платформы на базе искуственного интеллекта LibreChat, позволяющая нарушителю получить несанкционированный доступ к защищаемой информации
EPSS
7.6 High
CVSS3