Denial of Service Vulnerability in LibreChat by Danny Avila
CVE-2025-7105
5.7MEDIUM
What is CVE-2025-7105?
A vulnerability in LibreChat enables attackers to abuse the unrestricted Fork Function located in /api/convos/fork. By forking multiple contents rapidly, particularly those including large Mermaid graphs, the service may experience a JavaScript heap out of memory error when restarted, leading to a denial of service. This affects the latest version of LibreChat, making it crucial for users to address this issue to maintain service availability.
Affected Version(s)
danny-avila/librechat < unspecified
