Critical Analysis: CVE-2026-44653 - LibreChat is an enhanced ChatGPT clone that supports multipl... — June 8, 2026
Published 08 Jun 2026 · vulnerability management, CVE analysis, threat intelligence, security operations, cybersecurity news
AGMP Partners Initial Discovery and Context Alright, let's cut straight to the chase. CVE-2026-44653 dropped on June 8, 2026, and it's a significant one, particularly for organizations leveraging LibreChat in their internal or external-facing infrastructure. LibreChat, for those unfamiliar, positions itself as an "enhanced ChatGPT clone," supporting multiple AI providers. It's gained traction by offering a highly customizable and self-hostable solution for integrating large language models (LLMs) into workflows. This CVE, however, exposes a critical flaw: users with merely VIEW access to a Managed Chat Proxy (MCP) server instance can retrieve the server's decrypted secrets. This isn't just a data leakage scenario; it's a direct route to credential exposure, compromising the very AI services LibreChat is designed to front. The affected versions are LibreChat up to and including 0.8.3. Thi