CVE-2026-31945: LibreChat is a ChatGPT clone with additional features. Versions 0.8.2-rc2 through 0.8.2 are vulnerable to a server-side request forgery (SSRF) attack when using agent actions or MCP. Although a pre...

Added to the CISA Known Exploited Vulnerabilities catalog on 27 Mar 2026. Vendor: AI/ML. Product: chatgpt. CVSS score: 7.7.

LibreChat is a ChatGPT clone with additional features. Versions 0.8.2-rc2 through 0.8.2 are vulnerable to a server-side request forgery (SSRF) attack when using agent actions or MCP. Although a previous SSRF vulnerability (https://github.com/danny-avila/LibreChat/security/advisories/GHSA-rgjq-4q5...

Required action: Review and patch if applicable to your AI infrastructure.