CVE-2026-54029: LibreChat is an enhanced ChatGPT clone that supports multiple AI providers. Prior to 0.8.4-rc1, the DELETE /api/messages/:conversationId/:messageId endpoint allows any authenticated user to delete ...

Added to the CISA Known Exploited Vulnerabilities catalog on 25 Jun 2026. Vendor: AI/ML. Product: chatgpt. CVSS score: 5.3.

LibreChat is an enhanced ChatGPT clone that supports multiple AI providers. Prior to 0.8.4-rc1, the DELETE /api/messages/:conversationId/:messageId endpoint allows any authenticated user to delete any other user's messages. The validateMessageReq middleware only validates that the conversationId ...

Required action: Review and patch if applicable to your AI infrastructure.