CVE-2026-31942: LibreChat is an enhanced ChatGPT clone that supports multiple AI providers. In versions up to and including 0.7.6, an Insecure Direct Object Reference (IDOR) vulnerability exists in the API keys ma...
Added to the CISA Known Exploited Vulnerabilities catalog on 02 Jun 2026. Vendor: AI/ML. Product: chatgpt. CVSS score: 7.1.
LibreChat is an enhanced ChatGPT clone that supports multiple AI providers. In versions up to and including 0.7.6, an Insecure Direct Object Reference (IDOR) vulnerability exists in the API keys management endpoint (PUT /api/keys). Due to the use of the JavaScript object spread operator after set...
Required action: Review and patch if applicable to your AI infrastructure.