LIVE · cybersecurity feed
Live wire
vendor

Librechat

10 CVEs published in the last four months. Exploited flaws first.

Critical1
High7
Medium2
Exploited (KEV)0

All recent CVEs

CVECVSSSeverityProductSummaryPublished
CVE-2026-326259.6criticallibrechatLibreChat is an enhanced ChatGPT clone that supports multiple AI providers.95d ago
CVE-2026-446548.1highlibrechatLibreChat is an enhanced ChatGPT clone that supports multiple AI providers.95d ago
CVE-2026-540308highlibrechatLibreChat is an enhanced ChatGPT clone that supports multiple AI providers.72d ago
CVE-2025-412588highlibrechatLibreChat version 0.8.1-rc2 uses the same JWT secret for the user session mechanism and RAG API which compromises 171d ago
CVE-2026-540337.7highlibrechatLibreChat is an enhanced ChatGPT clone that supports multiple AI providers.72d ago
CVE-2026-319447.6highlibrechatLibreChat is a ChatGPT clone with additional features.176d ago
CVE-2026-42767.5highlibrechatLibreChat RAG API, version 0.7.0, contains a log-injection vulnerability that allows attackers to forge log entries173d ago
CVE-2026-319427.1highlibrechatLibreChat is an enhanced ChatGPT clone that supports multiple AI providers.95d ago
CVE-2026-319496.5mediumlibrechatLibreChat is a ChatGPT clone with additional features.176d ago
CVE-2026-332656.3mediumlibrechatIn LibreChat 0.8.1-rc2, a logged-in user obtains a JWT for both the LibreChat API and the RAG API.171d ago

Filter the full tracker by Librechat