Arbitrary Header Injection in LibreChat by vendor Danny Avila
CVE-2026-31951
6.8MEDIUM
What is CVE-2026-31951?
The vulnerability in LibreChat allows attackers to create malicious Model Context Protocol (MCP) servers that can inject arbitrary HTTP headers. This flaw affects versions 0.8.2-rc1 through 0.8.3-rc1, enabling exfiltration of sensitive OAuth tokens, such as {{LIBRECHAT_OPENID_ACCESS_TOKEN}}, when users interact with compromised servers. The vulnerability has been addressed in version 0.8.3-rc2.
Affected Version(s)
LibreChat >= v0.8.2-rc1, <= v0.8.3-rc1
