CVE-2026-31949: LibreChat is a ChatGPT clone with additional features. Prior to 0.8.3-rc1, a Denial of Service (DoS) vulnerability exists in the DELETE /api/convos endpoint that allows an authenticated attacker to...

Added to the CISA Known Exploited Vulnerabilities catalog on 13 Mar 2026. Vendor: AI/ML. Product: chatgpt. CVSS score: 6.5.

LibreChat is a ChatGPT clone with additional features. Prior to 0.8.3-rc1, a Denial of Service (DoS) vulnerability exists in the DELETE /api/convos endpoint that allows an authenticated attacker to crash the Node.js server process by sending malformed requests. The DELETE /api/convos route handle...

Required action: Review and patch if applicable to your AI infrastructure.