CVE-2026-32625: LibreChat is an enhanced ChatGPT clone that supports multiple AI providers. In versions up to and including 0.8.3, the Model Context Protocol (MCP) server integration resolves ${VAR} placeholders a...

Added to the CISA Known Exploited Vulnerabilities catalog on 02 Jun 2026. Vendor: AI/ML. Product: chatgpt. CVSS score: 9.6.

LibreChat is an enhanced ChatGPT clone that supports multiple AI providers. In versions up to and including 0.8.3, the Model Context Protocol (MCP) server integration resolves ${VAR} placeholders against the server's process.env during Zod schema validation of user-supplied MCP server URLs. Any a...

Required action: Review and patch if applicable to your AI infrastructure.