CVE-2026-54024: LibreChat is an enhanced ChatGPT clone that supports multiple AI providers. Prior to 0.8.4-rc1, the fix for CVE-2024-11171 (commit bb58a2d0) added limits: { fileSize } to createMulterInstance() in ...
Added to the CISA Known Exploited Vulnerabilities catalog on 25 Jun 2026. Vendor: AI/ML. Product: chatgpt. CVSS score: 6.5.
LibreChat is an enhanced ChatGPT clone that supports multiple AI providers. Prior to 0.8.4-rc1, the fix for CVE-2024-11171 (commit bb58a2d0) added limits: { fileSize } to createMulterInstance() in the file upload routes. However, the POST /api/convos/import endpoint uses a separate multer instanc...
Required action: Review and patch if applicable to your AI infrastructure.