librechat vulnerabilities

Direct Vulnerabilities

Known vulnerabilities in the librechat package. This does not include vulnerabilities belonging to this package’s dependencies.

Fix vulnerabilities automatically

Snyk's AI Trust Platform automatically finds the best upgrade path and integrates with your development workflows. Secure your code at zero cost.

Fix for free
VulnerabilityVulnerable Version
  • L
GHSA-xpqw-6gx7-v673

<0.8.3-r0
  • L
GHSA-v2wj-7wpq-c8vv

<0.8.3-r0
  • L
CVE-2026-25679

<0.8.3-r0
  • L
GHSA-wc8c-qw6v-h7f6

<0.8.3-r0
  • L
Incorrect Authorization

<0.8.3-r0
  • L
CVE-2026-27139

<0.8.3-r0
  • M
Cross-site Scripting (XSS)

<0.8.3-r0
  • L
GHSA-vpq2-c234-7xj6

<0.8.3-r0
  • L
GHSA-ph5j-38mg-j6hp

<0.8.3-r0
  • L
Server-Side Request Forgery (SSRF)

<0.8.3-r0
  • L
CVE-2026-3449

<0.8.3-r0
  • L
GHSA-rv83-g57w-fr8j

<0.8.3-r0
  • L
GHSA-j3gx-2473-5fp8

<0.8.3-r0
  • L
GHSA-v34v-rq6j-cj6p

<0.8.3-r0
  • L
CVE-2026-27142

<0.8.3-r0
  • L
GHSA-j4j7-vw47-rhfq

<0.8.3-r0
  • L
GHSA-7hfw-r8qc-89v4

<0.8.3-r0
  • L
CVE-2026-27137

<0.8.3-r0
  • L
Improper Restriction of Recursive Entity References in DTDs ('XML Entity Expansion')

<0.8.3-r0
  • L
GHSA-5c6j-r48x-rmvq

<0.8.3-r0
  • L
CVE-2026-27138

<0.8.3-r0
  • L
GHSA-xf7r-hgr6-v32p

<0.8.2-r7
  • L
CVE-2026-2359

<0.8.2-r7
  • L
GHSA-v52c-386h-88mc

<0.8.2-r7
  • L
CVE-2026-3304

<0.8.2-r7
  • H
CVE-2026-3520

<0.8.2-r7
  • L
GHSA-5528-5vmv-3xc2

<0.8.2-r7
  • L
Algorithmic Complexity

<0.8.2-r6
  • L
GHSA-7r86-cg39-jmmj

<0.8.2-r6
  • L
Inefficient Regular Expression Complexity

<0.8.2-r6
  • C
Directory Traversal

<0.8.2-r6
  • L
GHSA-mw96-cpmx-2vgc

<0.8.2-r6
  • L
CVE-2026-2739

<0.8.2-r6
  • L
GHSA-378v-28hj-76wf

<0.8.2-r6
  • L
GHSA-gq3j-xvxp-8hrf

<0.8.2-r6
  • L
GHSA-23c5-xmqv-rm74

<0.8.2-r6
  • L
GHSA-fj3w-jwp8-x2g3

<0.8.2-r6
  • H
Buffer Overflow

<0.8.2-r6
  • H
Inefficient Regular Expression Complexity

<0.8.2-r5
  • L
GHSA-3ppc-4f35-3m26

<0.8.2-r5
  • L
GHSA-2g4f-4pwh-qvx6

<0.8.2-r4
  • L
Inefficient Regular Expression Complexity

<0.8.2-r4
  • L
GHSA-37qj-frw5-hhjh

<0.8.2-r3
  • L
Improper Restriction of Recursive Entity References in DTDs ('XML Entity Expansion')

<0.8.2-r3
  • L
Improper Input Validation

<0.8.2-r3
  • L
GHSA-jmr7-xgp7-cmfj

<0.8.2-r3
  • L
Server-Side Request Forgery (SSRF)

<0.8.2-r2
  • L
Race Condition

<0.8.2-r2
  • L
GHSA-8fgc-7cc6-rx7x

<0.8.2-r2
  • L
GHSA-43fc-jf86-j433

<0.8.2-r2
  • L
Server-Side Request Forgery (SSRF)

<0.8.2-r2
  • L
GHSA-345p-7cg4-v4c7

<0.8.2-r2
  • L
GHSA-38r7-794h-5758

<0.8.2-r2
  • L
Improper Check for Unusual or Exceptional Conditions

<0.8.2-r2
  • L
Inefficient Regular Expression Complexity

<0.8.2-r1
  • L
Information Exposure Through Caching

<0.8.2-r1
  • L
GHSA-6wqw-2p9w-4vw4

<0.8.2-r1
  • M
Information Exposure

<0.8.2-r1
  • M
Cross-site Scripting (XSS)

<0.8.2-r1
  • L
GHSA-7h2j-956f-4vf2

<0.8.2-r1
  • M
Improper Access Control

<0.8.2-r1
  • L
GHSA-9r54-q6cx-xmh5

<0.8.2-r1
  • M
Incorrect Regular Expression

<0.8.2-r1
  • L
GHSA-w332-q679-j88p

<0.8.2-r1
  • L
GHSA-r354-f388-2fhh

<0.8.2-r1
  • H
Improper Check or Handling of Exceptional Conditions

<0.8.0-r5
  • C
Improper Authorization

<0.8.01-r5
  • L
Improper Access Control

<0.8.1-r5
  • H
Server-Side Request Forgery (SSRF)

<0.8.1-r5
  • H
Resource Exhaustion

<0.8.1-r5
  • L
GHSA-73rr-hh4g-fpgx

<0.8.1-r5
  • L
GHSA-g9mf-h72j-4rw9

<0.8.1-r5
  • M
CVE-2025-13465

<0.8.2-r3
  • H
Allocation of Resources Without Limits or Throttling

<0.8.1-r5
  • L
GHSA-xxjr-mmjv-4gpg

<0.8.2-r3
  • L
GHSA-8r9q-7v3j-jr4g

<0.8.1-r4
  • H
Inefficient Regular Expression Complexity

<0.8.1-r4
  • H
Improper Validation of Syntactic Correctness of Input

<0.8.0-r1
  • H
Server-Side Request Forgery (SSRF)

<0.8.1-r0
  • L
GHSA-wqch-xfxh-vrr4

<0.8.1-r0
  • L
CVE-2025-13204

<0.8.1-r0
  • L
GHSA-6rw7-vpxm-498p

<0.8.1-r2
  • L
Arbitrary Code Injection

<0.8.1-r0
  • L
GHSA-jc85-fpwf-qm7x

<0.8.1-r0
  • L
CVE-2025-15284

<0.8.1-r2
  • L
GHSA-8gw3-rxh4-v6jx

<0.8.1-r0
  • L
CVE-2025-13466

<0.8.1-r0
  • L
GHSA-r399-636x-v7f6

<0.8.1-r1
  • C
Deserialization of Untrusted Data

<0.8.1-r1
  • M
Cross-site Scripting (XSS)

<0.8.2-r1
  • M
Cross-site Scripting (XSS)

<0.8.1-r0
  • M
Improper Input Validation

<0.8.1-r0
  • L
Improper Verification of Cryptographic Signature

<0.8.0-r8
  • L
GHSA-869p-cjfg-cm3x

<0.8.0-r8
  • L
GHSA-w48q-cv73-mx4w

<0.8.0-r6
  • H
Insecure Default Initialization of Resource

<0.8.0-r6
  • L
GHSA-4fh9-h7wg-q85m

<0.8.0-r6
  • M
CVE-2025-66400

<0.8.0-r6
  • L
GHSA-pj86-cfqh-vqx6

<0.8.0-r5
  • L
GHSA-rcmh-qjqh-p98v

<0.8.0-r5
  • L
Improperly Controlled Modification of Dynamically-Determined Object Attributes

<0.8.0-r5
  • L
Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')

<0.8.0-r4
  • L
GHSA-mh29-5h37-fv8m

<0.8.0-r4
  • L
GHSA-93m4-6634-74q7

<0.8.0-r2
  • L
Directory Traversal

<0.8.0-r2
  • L
GHSA-mm7p-fcc7-pg87

<0.8.0-r1