OAuth Token Vulnerability in LibreChat by LibreChat
CVE-2026-31944
7.6HIGH
What is CVE-2026-31944?
The OAuth callback endpoint in LibreChat versions 0.8.2 to 0.8.2-rc3 allows an unauthorized user to store OAuth tokens intended for another user. This flaw enables an attacker to exploit the authorization process by tricking a victim into completing the OAuth flow, resulting in unauthorized access to the victim's services linked through the Model Context Protocol (MCP). The issue is resolved in version 0.8.3-rc1, thus users are advised to upgrade to this version to mitigate potential risks.
Affected Version(s)
LibreChat >= v0.8.2, <= 0.8.2-rc3
