Access Control Vulnerability in LibreChat by Danny Avila
CVE-2025-69220
7.1HIGH
What is CVE-2025-69220?
LibreChat, a ChatGPT clone with enhanced features, has a vulnerability where version 0.8.1-rc2 fails to enforce proper access control for file uploads. This allows an authenticated attacker, possessing the agent ID, to alter the functioning of arbitrary agents by uploading files, regardless of their permissions. This issue is resolved in version 0.8.2-rc2, emphasizing the importance of secure file management and access verification.
Affected Version(s)
LibreChat >= 0.8.1-rc2, < 0.8.2-rc2
