CVE-2026-31950: LibreChat is a ChatGPT clone with additional features. In versions 0.8.2-rc2 through 0.8.2-rc3, the SSE streaming endpoint `/api/agents/chat/stream/:streamId` does not verify that the requesting us...
Added to the CISA Known Exploited Vulnerabilities catalog on 27 Mar 2026. Vendor: AI/ML. Product: chatgpt. CVSS score: 5.3.
LibreChat is a ChatGPT clone with additional features. In versions 0.8.2-rc2 through 0.8.2-rc3, the SSE streaming endpoint `/api/agents/chat/stream/:streamId` does not verify that the requesting user owns the stream. Any authenticated user who obtains or guesses a valid stream ID can subscribe an...
Required action: Review and patch if applicable to your AI infrastructure.