
CVE-2025-41258 LibreChat version 0.8.1-rc2 uses the same JWT secret for the user session mechanism and RAG API which compromises the service-level authentication of the RAG API. https://www.cve.org/CVERecord?id=CVE-2025-41258
Post summary
The CVE-2025-41258 vulnerability in LibreChat arises from using the same JWT secret for session and RAG API authentication, exposing the service to compromise.


