CVE-2026-31944: LibreChat is a ChatGPT clone with additional features. From 0.8.2 to 0.8.2-rc3, The MCP (Model Context Protocol) OAuth callback endpoint accepts the redirect from the identity provider and stores O...
Added to the CISA Known Exploited Vulnerabilities catalog on 13 Mar 2026. Vendor: AI/ML. Product: chatgpt. CVSS score: 7.6.
LibreChat is a ChatGPT clone with additional features. From 0.8.2 to 0.8.2-rc3, The MCP (Model Context Protocol) OAuth callback endpoint accepts the redirect from the identity provider and stores OAuth tokens for the user who initiated the flow, without verifying that the browser hitting the redi...
Required action: Review and patch if applicable to your AI infrastructure.