CVE-2026-44654: LibreChat is an enhanced ChatGPT clone that supports multiple AI providers. In versions up to and including 0.8.3, a shared-agent editor can delete file records through `DELETE /api/files` that the...
Added to the CISA Known Exploited Vulnerabilities catalog on 02 Jun 2026. Vendor: AI/ML. Product: chatgpt.
LibreChat is an enhanced ChatGPT clone that supports multiple AI providers. In versions up to and including 0.8.3, a shared-agent editor can delete file records through `DELETE /api/files` that the owner has reused across multiple agents. The deletion removes the file globally — not just from the...
Required action: Review and patch if applicable to your AI infrastructure.