CVE-2026-34371: LibreChat is a ChatGPT clone with additional features. Prior to 0.8.4, LibreChat trusts the name field returned by the execute_code sandbox when persisting code-generated artifacts. On deployments ...

Added to the CISA Known Exploited Vulnerabilities catalog on 07 Apr 2026. Vendor: AI/ML. Product: chatgpt. CVSS score: 6.3.

LibreChat is a ChatGPT clone with additional features. Prior to 0.8.4, LibreChat trusts the name field returned by the execute_code sandbox when persisting code-generated artifacts. On deployments using the default local file strategy, a malicious artifact filename containing traversal sequences ...

Required action: Review and patch if applicable to your AI infrastructure.