CVE-2026-31951: LibreChat is a ChatGPT clone with additional features. In versions 0.8.2-rc1 through 0.8.3-rc1, user-created MCP (Model Context Protocol) servers can include arbitrary HTTP headers that undergo cre...
Added to the CISA Known Exploited Vulnerabilities catalog on 27 Mar 2026. Vendor: AI/ML. Product: chatgpt. CVSS score: 6.8.
LibreChat is a ChatGPT clone with additional features. In versions 0.8.2-rc1 through 0.8.3-rc1, user-created MCP (Model Context Protocol) servers can include arbitrary HTTP headers that undergo credential placeholder substitution. An attacker can create a malicious MCP server with headers contain...
Required action: Review and patch if applicable to your AI infrastructure.