CVE-2026-54027: LibreChat is an enhanced ChatGPT clone that supports multiple AI providers. Prior to 0.8.4-rc1, the POST /api/files/images endpoint allows any authenticated user to upload files into any agent's to...
Added to the CISA Known Exploited Vulnerabilities catalog on 25 Jun 2026. Vendor: AI/ML. Product: chatgpt. CVSS score: 6.5.
LibreChat is an enhanced ChatGPT clone that supports multiple AI providers. Prior to 0.8.4-rc1, the POST /api/files/images endpoint allows any authenticated user to upload files into any agent's tool_resources (e.g., context, execute_code) without verifying ownership or EDIT permission on the tar...
Required action: Review and patch if applicable to your AI infrastructure.