CVE-2026-54029: LibreChat is an enhanced ChatGPT clone that supports multiple AI providers. Prior to 0.8.4-rc1, the DELETE /api/messages/:conversationId/:messageId endpoint allows any authenticated user to delete ...
Added to the CISA Known Exploited Vulnerabilities catalog on 25 Jun 2026. Vendor: AI/ML. Product: chatgpt. CVSS score: 5.3.
LibreChat is an enhanced ChatGPT clone that supports multiple AI providers. Prior to 0.8.4-rc1, the DELETE /api/messages/:conversationId/:messageId endpoint allows any authenticated user to delete any other user's messages. The validateMessageReq middleware only validates that the conversationId ...
Required action: Review and patch if applicable to your AI infrastructure.