CVE-2026-44653: LibreChat is an enhanced ChatGPT clone that supports multiple AI providers. In versions up to and including 0.8.3, users with only `VIEW` access to an MCP server can retrieve the server's decrypted...
Added to the CISA Known Exploited Vulnerabilities catalog on 02 Jun 2026. Vendor: AI/ML. Product: chatgpt. CVSS score: 6.5.
LibreChat is an enhanced ChatGPT clone that supports multiple AI providers. In versions up to and including 0.8.3, users with only `VIEW` access to an MCP server can retrieve the server's decrypted admin-managed secrets through `GET /api/mcp/servers` and `GET /api/mcp/servers/:serverName`. The re...
Required action: Review and patch if applicable to your AI infrastructure.