librechat

Direct Vulnerabilities

Known vulnerabilities in the librechat package. This does not include vulnerabilities belonging to this package’s dependencies.

Fix vulnerabilities automatically

Snyk's AI Trust Platform automatically finds the best upgrade path and integrates with your development workflows. Secure your code at zero cost.

Fix for free
VulnerabilityVulnerable Version
  • L
CVE-2026-41139

<0.8.4-r5
  • C
Arbitrary Code Injection

<0.8.4-r5
  • L
Improper Input Validation

<0.8.4-r5
  • L
Directory Traversal

<0.8.4-r5
  • L
GHSA-xq3m-2v4x-88gg

<0.8.4-r5
  • L
GHSA-r4q5-vmmm-2653

<0.8.4-r5
  • M
Directory Traversal

<0.8.4-r5
  • L
GHSA-xpcf-pg52-r92g

<0.8.4-r5
  • L
GHSA-fvcv-3m26-pcqx

<0.8.4-r5
  • L
GHSA-3p68-rc4w-qgx5

<0.8.4-r5
  • L
GHSA-fw9q-39r9-c252

<0.8.4-r5
  • L
GHSA-458j-xx4x-4375

<0.8.4-r5
  • L
Improperly Controlled Modification of Dynamically-Determined Object Attributes

<0.8.4-r5
  • L
GHSA-39q2-94rc-95cp

<0.8.4-r5
  • L
GHSA-92pp-h63x-v22m

<0.8.4-r5
  • M
CVE-2026-2950

<0.8.4-r5
  • L
GHSA-r5fr-rjxr-66jc

<0.8.4-r5
  • H
Directory Traversal

<0.8.4-r5
  • L
GHSA-rr7j-v2q5-chgv

<0.8.4-r5
  • M
HTTP Response Splitting

<0.8.4-r5
  • L
GHSA-vvjj-xcjg-gr5g

<0.8.4-r5
  • L
GHSA-f23m-r3pf-42rh

<0.8.4-r5
  • L
GHSA-xf4j-xp2r-rqqx

<0.8.4-r5
  • L
GHSA-r5rp-j6wh-rvv4

<0.8.4-r5
  • M
Incorrect Behavior Order: Validate Before Canonicalize

<0.8.4-r5
  • L
GHSA-wmmm-f939-6g9c

<0.8.4-r5
  • L
GHSA-jvff-x2qm-6286

<0.8.4-r5
  • C
CVE-2026-4800

<0.8.4-r5
  • L
Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')

<0.8.4-r5
  • C
Unintended Proxy or Intermediary ('Confused Deputy')

<0.8.4-r5
  • L
GHSA-29qv-4j9f-fjw5

<0.8.4-r5
  • L
GHSA-26pp-8wgv-hjvm

<0.8.4-r5
  • L
CVE-2026-1526

<0.8.4-r3
  • L
CVE-2026-1527

<0.8.4-r3
  • L
CVE-2026-2581

<0.8.4-r3
  • L
GHSA-v8w9-8mx6-g223

<0.8.4-r3
  • L
Improper Validation of Specified Quantity in Input

<0.8.4-r3
  • L
Cross-site Scripting (XSS)

<0.8.4-r3
  • M
Off-by-one Error

<0.8.4-r3
  • L
Uncontrolled Recursion

<0.8.4-r3
  • L
GHSA-gmq8-994r-jv83

<0.8.4-r3
  • L
GHSA-8gc5-j5rx-235r

<0.8.4-r3
  • L
GHSA-jp2q-39xq-3w4g

<0.8.4-r3
  • L
GHSA-rf6f-7fwh-wjgh

<0.8.4-r3
  • L
Loop with Unreachable Exit Condition ('Infinite Loop')

<0.8.4-r3
  • L
Improper Restriction of Recursive Entity References in DTDs ('XML Entity Expansion')

<0.8.4-r3
  • L
GHSA-2mjp-6q6p-2qxm

<0.8.4-r3
  • L
GHSA-v9p9-hfj2-hcw8

<0.8.4-r3
  • L
CVE-2026-1528

<0.8.4-r3
  • L
GHSA-f269-vfmq-vjvj

<0.8.4-r3
  • L
GHSA-25h7-pfq9-p65f

<0.8.4-r3
  • L
GHSA-phc3-fgpg-7m6h

<0.8.4-r3
  • L
GHSA-vrm6-8vpv-qv8q

<0.8.4-r3
  • L
GHSA-5v7r-6r5c-r473

<0.8.4-r3
  • L
GHSA-mr9r-mww3-v6gv

<0.8.4-r3
  • L
GHSA-qj8w-gfj5-8c6v

<0.8.4-r5
  • L
CVE-2026-2229

<0.8.4-r3
  • H
Resource Exhaustion

<0.8.4-r5
  • C
Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')

<0.8.4-r3
  • L
GHSA-4992-7rv2-5pvq

<0.8.4-r3
  • C
CVE-2026-1525

<0.8.4-r3
  • L
Inappropriate Comment Style

<0.8.3-r1
  • C
Improper Handling of URL Encoding (Hex Encoding)

<0.8.3-r1
  • L
GHSA-w7fw-mjwx-w883

<0.8.3-r1
  • L
GHSA-5pq2-9x2x-5p6w

<0.8.3-r1
  • H
CVE-2026-2391

<0.8.3-r1
  • L
Arbitrary Code Injection

<0.8.3-r1
  • L
GHSA-p6xx-57qc-3wxr

<0.8.3-r1
  • L
GHSA-q5qw-h33p-qvwr

<0.8.3-r1
  • L
GHSA-xpqw-6gx7-v673

<0.8.3-r0
  • L
GHSA-v2wj-7wpq-c8vv

<0.8.3-r0
  • L
Direct Request ('Forced Browsing')

<0.8.3-r0
  • L
GHSA-wc8c-qw6v-h7f6

<0.8.3-r0
  • L
Incorrect Authorization

<0.8.3-r0
  • L
Directory Traversal

<0.8.3-r0
  • M
Cross-site Scripting (XSS)

<0.8.3-r0
  • L
GHSA-vpq2-c234-7xj6

<0.8.3-r0
  • L
GHSA-ph5j-38mg-j6hp

<0.8.3-r0
  • L
Server-Side Request Forgery (SSRF)

<0.8.3-r0
  • L
CVE-2026-3449

<0.8.3-r0
  • L
GHSA-rv83-g57w-fr8j

<0.8.3-r0
  • L
GHSA-j3gx-2473-5fp8

<0.8.3-r0
  • L
GHSA-v34v-rq6j-cj6p

<0.8.3-r0
  • L
Cross-site Scripting (XSS)

<0.8.3-r0
  • L
GHSA-j4j7-vw47-rhfq

<0.8.3-r0
  • L
GHSA-7hfw-r8qc-89v4

<0.8.3-r0
  • L
Improper Certificate Validation

<0.8.3-r0
  • L
Improper Restriction of Recursive Entity References in DTDs ('XML Entity Expansion')

<0.8.3-r0
  • L
GHSA-5c6j-r48x-rmvq

<0.8.3-r0
  • L
Improper Certificate Validation

<0.8.3-r0
  • L
GHSA-xf7r-hgr6-v32p

<0.8.2-r7
  • H
CVE-2026-2359

<0.8.2-r7
  • L
GHSA-v52c-386h-88mc

<0.8.2-r7
  • H
CVE-2026-3304

<0.8.2-r7
  • H
CVE-2026-3520

<0.8.2-r7
  • L
GHSA-5528-5vmv-3xc2

<0.8.2-r7
  • L
Algorithmic Complexity

<0.8.2-r6
  • L
GHSA-7r86-cg39-jmmj

<0.8.2-r6
  • L
Inefficient Regular Expression Complexity

<0.8.2-r6
  • C
Directory Traversal

<0.8.2-r6
  • L
GHSA-mw96-cpmx-2vgc

<0.8.2-r6
  • L
CVE-2026-2739

<0.8.2-r6
  • L
GHSA-378v-28hj-76wf

<0.8.2-r6
  • L
GHSA-gq3j-xvxp-8hrf

<0.8.2-r6
  • L
GHSA-23c5-xmqv-rm74

<0.8.2-r6
  • L
GHSA-fj3w-jwp8-x2g3

<0.8.2-r6
  • H
Buffer Overflow

<0.8.2-r6
  • H
Inefficient Regular Expression Complexity

<0.8.2-r5
  • L
GHSA-3ppc-4f35-3m26

<0.8.2-r5
  • L
GHSA-2g4f-4pwh-qvx6

<0.8.2-r4
  • L
Inefficient Regular Expression Complexity

<0.8.2-r4
  • L
GHSA-37qj-frw5-hhjh

<0.8.2-r3
  • L
Improper Restriction of Recursive Entity References in DTDs ('XML Entity Expansion')

<0.8.2-r3
  • L
Improper Input Validation

<0.8.2-r3
  • L
GHSA-jmr7-xgp7-cmfj

<0.8.2-r3
  • L
Server-Side Request Forgery (SSRF)

<0.8.2-r2
  • L
Race Condition

<0.8.2-r2
  • L
GHSA-8fgc-7cc6-rx7x

<0.8.2-r2
  • L
GHSA-43fc-jf86-j433

<0.8.2-r2
  • L
Server-Side Request Forgery (SSRF)

<0.8.2-r2
  • L
GHSA-345p-7cg4-v4c7

<0.8.2-r2
  • L
GHSA-38r7-794h-5758

<0.8.2-r2
  • L
Improper Check for Unusual or Exceptional Conditions

<0.8.2-r2
  • L
Inefficient Regular Expression Complexity

<0.8.2-r1
  • L
Information Exposure Through Caching

<0.8.2-r1
  • L
GHSA-6wqw-2p9w-4vw4

<0.8.2-r1
  • M
Information Exposure

<0.8.2-r1
  • M
Cross-site Scripting (XSS)

<0.8.2-r1
  • L
GHSA-7h2j-956f-4vf2

<0.8.2-r1
  • M
Improper Access Control

<0.8.2-r1
  • L
GHSA-9r54-q6cx-xmh5

<0.8.2-r1
  • M
Incorrect Regular Expression

<0.8.2-r1
  • L
GHSA-w332-q679-j88p

<0.8.2-r1
  • L
GHSA-r354-f388-2fhh

<0.8.2-r1
  • H
Improper Check or Handling of Exceptional Conditions

<0.8.0-r5
  • C
Improper Authorization

<0.8.01-r5
  • L
Improper Access Control

<0.8.1-r5
  • H
Server-Side Request Forgery (SSRF)

<0.8.1-r5
  • H
Resource Exhaustion

<0.8.1-r5
  • L
GHSA-73rr-hh4g-fpgx

<0.8.1-r5
  • L
GHSA-g9mf-h72j-4rw9

<0.8.1-r5
  • M
CVE-2025-13465

<0.8.2-r3
  • H
Allocation of Resources Without Limits or Throttling

<0.8.1-r5
  • L
GHSA-xxjr-mmjv-4gpg

<0.8.2-r3
  • L
GHSA-8r9q-7v3j-jr4g

<0.8.1-r4
  • H
Inefficient Regular Expression Complexity

<0.8.1-r4
  • H
Improper Validation of Syntactic Correctness of Input

<0.8.0-r1
  • H
Server-Side Request Forgery (SSRF)

<0.8.1-r0
  • L
GHSA-wqch-xfxh-vrr4

<0.8.1-r0
  • L
CVE-2025-13204

<0.8.1-r0
  • L
GHSA-6rw7-vpxm-498p

<0.8.1-r2
  • L
CVE-2025-15284

<0.8.1-r2
  • L
GHSA-8gw3-rxh4-v6jx

<0.8.1-r0
  • L
CVE-2025-13466

<0.8.1-r0
  • L
GHSA-r399-636x-v7f6

<0.8.1-r1
  • C
Deserialization of Untrusted Data

<0.8.1-r1
  • M
Cross-site Scripting (XSS)

<0.8.2-r1
  • M
Cross-site Scripting (XSS)

<0.8.1-r0
  • M
Improper Input Validation

<0.8.1-r0
  • L
Improper Verification of Cryptographic Signature

<0.8.0-r8
  • L
GHSA-869p-cjfg-cm3x

<0.8.0-r8
  • L
GHSA-w48q-cv73-mx4w

<0.8.0-r6
  • H
Insecure Default Initialization of Resource

<0.8.0-r6
  • L
GHSA-4fh9-h7wg-q85m

<0.8.0-r6
  • M
CVE-2025-66400

<0.8.0-r6
  • L
GHSA-pj86-cfqh-vqx6

<0.8.0-r5
  • L
GHSA-rcmh-qjqh-p98v

<0.8.0-r5
  • L
Improperly Controlled Modification of Dynamically-Determined Object Attributes

<0.8.0-r5
  • L
Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')

<0.8.0-r4
  • L
GHSA-mh29-5h37-fv8m

<0.8.0-r4
  • L
Directory Traversal

<0.8.0-r2