CVE-2026-31942General(librechat / librechat)

LOWCVSS 7.1 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch librechat librechat systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

LibreChat is an enhanced ChatGPT clone that supports multiple AI providers. In versions up to and including 0.7.6, an Insecure Direct Object Reference (IDOR) vulnerability exists in the API keys management endpoint (PUT /api/keys). Due to the use of the JavaScript object spread operator after setting the authenticated user's ID, any authenticated user can inject a userId parameter in the request body to overwrite any other user's API keys (e.g., OpenAI, Anthropic, Azure). This allows an attacker to replace a victim's API key configuration, potentially routing the victim's conversations through attacker-controlled keys or denying service by providing invalid keys. This is patched in version 0.8.3-rc1.

0.8/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-862

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • librechat

Threat summary

  • Patch or workaround signal is available
  • 11 mentions across 10 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 4 signals
  • Technical details provided in 4 signals
  • General: 6 classified signals
  • Disclosure: 3 classified signals
  • Peaked 5d ago at 2 mentions (2026-06-26); latest day: 1
  • 11 total mentions across 10 days

Affected systems

Vendors
Products
librechat

Deep dive

Activity timeline11 mentions / 10d
01122Mentions · 2026-03-25: 1Mentions · 2026-06-03: 1Mentions · 2026-06-19: 1Mentions · 2026-06-22: 1Mentions · 2026-06-26: 2Mentions · 2026-06-27: 1Mentions · 2026-07-03: 1Mentions · 2026-07-07: 1Mentions · 2026-07-09: 1Mentions · 2026-07-10: 1Patch / Workaround · 2026-06-22: 1Patch / Workaround · 2026-07-03: 1Patch / Workaround · 2026-07-09: 1Patch / Workaround · 2026-07-10: 1Technical Details · 2026-06-03: 1Technical Details · 2026-06-22: 1Technical Details · 2026-07-03: 1Technical Details · 2026-07-10: 103-2506-0306-1906-2206-2606-2707-0307-0707-0907-10
Signal classification3 categories
General
654.5%
Disclosure
327.3%
Patch
218.2%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-03-251
General1
2026-06-031
Disclosure1
2026-06-191
General1
2026-06-221
Disclosure1
2026-06-262
General2
2026-06-271
General1
2026-07-031
Patch1
2026-07-071
General1
2026-07-091
Disclosure1
2026-07-101
Patch1
Full discourse11 posts
  • 秋风@q1uf3ng
    General

    What are the limits of AI-assisted vulnerability hunting? I obtained 23 CVEs in one month. BentoML 8.2k CVE-2026-27905 HIGH SillyTavern 24.6k CVE-2026-26286 HIGH Plane 28.2k CVE-2026-27705 MEDIUM NocoDB 46.4k CVE-2026-28399 MEDIUM Mautic 8.4k CVE-2026-3105 HIGH File Browser 27.9k CVE-2026-28492 HIGH OpenReplay 7.3k CVE-2026-28443 MEDIUM SuiteCRM 4.0k CVE-2026-29096 HIGH Pimcore 3.6k CVE-2026-27461 HIGH Craft CMS 5.2k CVE-2026-32263 MEDIUM Froxlor 1.6k CVE-2026-30932 HIGH Actual Budget 3.2k CVE-2026-27638 HIGH Lemmy 14.0k CVE-2026-29178 MEDIUM Chartbrew 2.6k CVE-2026-27005 HIGH Tautulli 1.7k CVE-2026-28505 HIGH Typebot 9.5k CVE-2026-33712 CRITICAL LibreChat 34.7k CVE-2026-31942 HIGH Coolify 33.8k CVE-2026-27883 HIGH Gotenberg 3.0k CVE-2026-27018 HIGH Unkey 5.2k CVE-2026-28339 MEDIUM Piwigo 3.3k CVE-2026-27634 CRITICAL Pixelfed 10.7k CVE-2026-27011 HIGH Follow (Folo) 3.0k CVE-2026-27499 HIGH

    Post summary

    The post lists multiple new CVEs with severity ratings but offers no further technical details, exploitation evidence, or patch information.

    720220514825.9K
    1.7K followersView on X
  • ケイ | IT・セキュリティ系副業Webライター@Teeeda_worker
    Patch

    CVE-2026-31942 LibreChat バージョン0.7.6までの脆弱性をわかりやすく解説|影響範囲と対策まとめ https://www.cybernote.click/2026/07/02/cve-2026-31942-librechat-076/ #IT #Security #cybersecurity

    Post summary

    The linked article provides an explanation of CVE-2026-31942 and summarizes countermeasures, indicating a patch or workaround is discussed, but no exploit code or active exploitation details are mentioned.

    0001049
    209 followersView on X
  • ケイ | IT・セキュリティ系副業Webライター@Teeeda_worker
    Patch

    CVE-2026-31942 LibreChat バージョン0.7.6までの脆弱性をわかりやすく解説|影響範囲と対策まとめ https://www.cybernote.click/2026/07/02/cve-2026-31942-librechat-076/ #IT #Security #cybersecurity

    Post summary

    The article provides an overview of CVE‑2026‑31942 affecting LibreChat up to version 0.7.6, including impact and mitigation steps.

    0000056
    206 followersView on X
  • ケイ | IT・セキュリティ系副業Webライター@Teeeda_worker
    Disclosure

    CVE-2026-31942 LibreChat バージョン0.7.6までの脆弱性をわかりやすく解説|影響範囲と対策まとめ https://www.cybernote.click/2026/07/02/cve-2026-31942-librechat-076/ #IT #Security #cybersecurity

    Post summary

    The text announces CVE‑2026‑31942, explains the vulnerability in LibreChat version 0.7.6, and highlights impact and mitigation measures.

    0000044
    207 followersView on X
  • ケイ | IT・セキュリティ系副業Webライター@Teeeda_worker
    General

    CVE-2026-31942 LibreChat バージョン0.7.6までの脆弱性をわかりやすく解説|影響範囲と対策まとめ https://www.cybernote.click/2026/07/02/cve-2026-31942-librechat-076/ #IT #Security #cybersecurity

    Post summary

    The article appears to provide a general overview of CVE‑2026‑31942 for LibreChat version 0.7.6, with no evidence of PoC, exploit code, active exploitation, patches, technical details, or debunking claims.

    0000060
    208 followersView on X
  • ケイ | IT・セキュリティ系副業Webライター@Teeeda_worker
    General

    CVE-2026-31942 LibreChat バージョン0.7.6までの脆弱性をわかりやすく解説|影響範囲と対策まとめ https://www.cybernote.click/2026/06/17/cve-2026-31942-librechat-076/ #IT #Security #cybersecurity

    Post summary

    The text references CVE-2026-31942 and links to an article that presumably covers its impact and mitigation, but provides no detailed technical information or exploit evidence.

    0000050
    208 followersView on X
  • ケイ | IT・セキュリティ系副業Webライター@Teeeda_worker
    General

    CVE-2026-31942 LibreChat バージョン0.7.6までの脆弱性をわかりやすく解説|影響範囲と対策まとめ https://www.cybernote.click/2026/06/17/cve-2026-31942-librechat-076/ #IT #Security #cybersecurity

    Post summary

    The text announces a post that explains CVE-2026-31942 for LibreChat versions up to 0.7.6, summarizing impacts and mitigations, but provides no technical, exploit, or patch details within the snippet.

    0000067
    208 followersView on X
  • ケイ | IT・セキュリティ系副業Webライター@Teeeda_worker
    General

    CVE-2026-31942 LibreChat バージョン0.7.6までの脆弱性をわかりやすく解説|影響範囲と対策まとめ https://www.cybernote.click/2026/06/17/cve-2026-31942-librechat-076/ #IT #Security #cybersecurity

    Post summary

    The text merely references an article that explains CVE-2026-31942 for LibreChat up to version 0.7.6, but provides no concrete evidence of a PoC, exploit, patch details, or technical specifics.

    0000051
    208 followersView on X
  • ケイ | IT・セキュリティ系副業Webライター@Teeeda_worker
    Disclosure

    CVE-2026-31942 LibreChat バージョン0.7.6までの脆弱性をわかりやすく解説|影響範囲と対策まとめ https://www.cybernote.click/2026/06/17/cve-2026-31942-librechat-076/ #IT #Security #cybersecurity

    Post summary

    The linked article provides an overview of CVE‑2026‑31942 in LibreChat 0.7.6, covering its impact, affected scope, and recommended mitigation measures.

    0000049
    208 followersView on X
  • ケイ | IT・セキュリティ系副業Webライター@Teeeda_worker
    General

    CVE-2026-31942 LibreChat バージョン0.7.6までの脆弱性をわかりやすく解説|影響範囲と対策まとめ https://www.cybernote.click/2026/06/17/cve-2026-31942-librechat-076/ #IT #Security #cybersecurity

    Post summary

    The post is a brief announcement that links to an article about CVE‑2026‑31942, but the snippet itself contains no explicit proof‑of‑concept, exploit code, or detailed mitigation instructions.

    0000049
    209 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-31942 LibreChat is an enhanced ChatGPT clone that supports multiple AI providers. In versions up to and including 0.7.6, an Insecure Direct Object Reference (IDOR) vulnerab… https://www.cve.org/CVERecord?id=CVE-2026-31942

    Post summary

    The post announces the CVE-2026-31942 IDOR vulnerability in LibreChat, providing minimal technical detail and no evidence of exploitation or mitigation.

    00000173
    57.6K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Applibrechatlibrechat---

Explore more