CVE-2026-22252Disclosure(librechat / librechat)

LOWCVSS 9.9 · CRITICAL

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

LibreChat is a ChatGPT clone with additional features. Prior to v0.8.2-rc2, LibreChat's MCP stdio transport accepts arbitrary commands without validation, allowing any authenticated user to execute shell commands as root inside the container through a single API request. This vulnerability is fixed in v0.8.2-rc2.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-285

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • librechat

Threat summary

  • 1 mentions across 1 observed day

What's happening

  • Technical details provided in 1 signal
  • Disclosure: 1 classified signal
  • 1 total mentions across 1 day

Affected systems

Vendors
Products
librechat

1 version affected across 1 product

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-04-24: 1Technical Details · 2026-04-24: 104-24
Signal classification1 categories
Disclosure
1100.0%
Full discourse1 post
  • MCPCIO-Model Context Protocol@robertmcpcio
    Disclosure

    "Works as designed" isn't the same as "safe by default." CVE-2026-22252 hit 7,000+ MCP servers across Python, TypeScript, Java, and Rust — Anthropic confirmed input sanitization is the developer's job. That gap is exactly where RCE lives. 🚨 https://t.co/oCwxvSe5oL

    Post summary

    The tweet announces the existence and scope of CVE‑2026‑22252, highlighting a remote code execution flaw across several programming languages, but does not provide a PoC, exploit, patch, or evidence of active exploitation.

    0010041
    9 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Applibrechatlibrechat0.8.2--

Explore more