librechat vulnerabilities

Direct Vulnerabilities

Known vulnerabilities in the librechat package. This does not include vulnerabilities belonging to this package’s dependencies.

Fix vulnerabilities automatically

Snyk's AI Trust Platform automatically finds the best upgrade path and integrates with your development workflows. Secure your code at zero cost.

Fix for free
VulnerabilityVulnerable Version
  • H
Improper Check or Handling of Exceptional Conditions

<0.8.0-r5
  • C
Improper Authorization

<0.8.01-r5
  • L
Improper Access Control

<0.8.1-r5
  • H
Server-Side Request Forgery (SSRF)

<0.8.1-r5
  • L
Resource Exhaustion

<0.8.1-r5
  • L
GHSA-73rr-hh4g-fpgx

<0.8.1-r5
  • L
GHSA-g9mf-h72j-4rw9

<0.8.1-r5
  • L
CVE-2025-13465

<0.8.1-r5
  • H
Allocation of Resources Without Limits or Throttling

<0.8.1-r5
  • L
GHSA-xxjr-mmjv-4gpg

<0.8.1-r5
  • L
GHSA-8r9q-7v3j-jr4g

<0.8.1-r4
  • H
Inefficient Regular Expression Complexity

<0.8.1-r4
  • H
Improper Validation of Syntactic Correctness of Input

<0.8.0-r1
  • H
Server-Side Request Forgery (SSRF)

<0.8.1-r0
  • L
GHSA-wqch-xfxh-vrr4

<0.8.1-r0
  • L
CVE-2025-13204

<0.8.1-r0
  • L
GHSA-6rw7-vpxm-498p

<0.8.1-r2
  • L
CVE-2025-12735

<0.8.1-r0
  • L
GHSA-jc85-fpwf-qm7x

<0.8.1-r0
  • L
CVE-2025-15284

<0.8.1-r2
  • L
GHSA-8gw3-rxh4-v6jx

<0.8.1-r0
  • L
CVE-2025-13466

<0.8.1-r0
  • L
GHSA-r399-636x-v7f6

<0.8.1-r1
  • C
Deserialization of Untrusted Data

<0.8.1-r1
  • M
Cross-site Scripting (XSS)

<0.8.1-r0
  • M
Improper Input Validation

<0.8.1-r0
  • L
Improper Verification of Cryptographic Signature

<0.8.0-r8
  • L
GHSA-869p-cjfg-cm3x

<0.8.0-r8
  • L
GHSA-w48q-cv73-mx4w

<0.8.0-r6
  • L
Insecure Default Initialization of Resource

<0.8.0-r6
  • L
GHSA-4fh9-h7wg-q85m

<0.8.0-r6
  • L
Improper Input Validation

<0.8.0-r6
  • L
GHSA-pj86-cfqh-vqx6

<0.8.0-r5
  • L
GHSA-rcmh-qjqh-p98v

<0.8.0-r5
  • L
Improperly Controlled Modification of Dynamically-Determined Object Attributes

<0.8.0-r5
  • L
Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')

<0.8.0-r4
  • L
GHSA-mh29-5h37-fv8m

<0.8.0-r4
  • L
GHSA-93m4-6634-74q7

<0.8.0-r2
  • L
Directory Traversal

<0.8.0-r2
  • L
GHSA-mm7p-fcc7-pg87

<0.8.0-r1