OAuth Token Vulnerability in LibreChat by LibreChat
CVE-2026-31944

7.6HIGH

Key Information:

Status
Vendor
CVE Published:
13 March 2026

What is CVE-2026-31944?

The OAuth callback endpoint in LibreChat versions 0.8.2 to 0.8.2-rc3 allows an unauthorized user to store OAuth tokens intended for another user. This flaw enables an attacker to exploit the authorization process by tricking a victim into completing the OAuth flow, resulting in unauthorized access to the victim's services linked through the Model Context Protocol (MCP). The issue is resolved in version 0.8.3-rc1, thus users are advised to upgrade to this version to mitigate potential risks.

Affected Version(s)

LibreChat >= v0.8.2, <= 0.8.2-rc3

References

CVSS V3.1

Score:
7.6
Severity:
HIGH
Confidentiality:
High
Integrity:
Low
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.