Denial of Service Vulnerability in LibreChat by Danny Avila
CVE-2025-8849
5.4MEDIUM
What is CVE-2025-8849?
LibreChat version 0.7.9 is susceptible to a Denial of Service attack stemming from unbounded parameter values in the /api/memories endpoint. The key and value parameters are not properly validated, allowing attackers to submit excessively large inputs. This flaw can induce a null pointer error in the Rust-based backend, disrupting the ability to create new memories and causing service instability.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
danny-avila/librechat < unspecified
References
CVSS V3.0
Score:
5.4
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
