CVE-2026-31943Disclosure(librechat / librechat)

LOWCVSS 8.5 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch librechat librechat systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

LibreChat is a ChatGPT clone with additional features. Prior to version 0.8.3, `isPrivateIP()` in `packages/api/src/auth/domain.ts` fails to detect IPv4-mapped IPv6 addresses in their hex-normalized form, allowing any authenticated user to bypass SSRF protection and make the server issue HTTP requests to internal network resources — including cloud metadata services (e.g., AWS `169.254.169.254`), loopback, and RFC1918 ranges. Version 0.8.3 fixes the issue.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-918

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • librechat

Threat summary

  • Patch or workaround signal is available
  • 4 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 4 signals
  • Disclosure: 2 classified signals
  • General: 1 classified signal
  • Peaked 1d ago at 3 mentions (2026-03-27); latest day: 1
  • 4 total mentions across 2 days

Affected systems

Vendors
Products
librechat

1 version affected across 1 product

Deep dive

Activity timeline4 mentions / 2d
01223Mentions · 2026-03-27: 3Mentions · 2026-03-28: 1Patch / Workaround · 2026-03-27: 1Technical Details · 2026-03-27: 3Technical Details · 2026-03-28: 103-2703-28
Signal classification3 categories
Disclosure
250.0%
General
125.0%
Patch
125.0%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-03-273
Disclosure1General1Patch1
2026-03-281
Disclosure1
Full discourse4 posts
  • CVE@CVEnew
    Disclosure

    CVE-2026-31943 LibreChat is a ChatGPT clone with additional features. Prior to version 0.8.3, `isPrivateIP()` in `packages/api/src/auth/domain.ts` fails to detect IPv4-mapped IPv6 a… https://www.cve.org/CVERecord?id=CVE-2026-31943

    Post summary

    CVE-2026-31943 is a newly disclosed vulnerability in LibreChat’s IP detection logic; no PoC, exploit, or patch has been shared.

    00000156
    56.9K followersView on X
  • The Hacker Wire@TheHackerWire
    Disclosure

    🟠 CVE-2026-31943 - High LibreChat is a ChatGPT clone with additional features. Prior to version 0.8.3, `isPrivateIP()` in `packages/api/src/auth/domain.ts` fails to detect IPv4-mapped IPv6 addresses in their hex-nor... https://www.thehackerwire.com/vulnerability/CVE-2026-31943/ https://t.co/MKlmjDGTn7

    Post summary

    The tweet announces CVE-2026-31943 in LibreChat, describing a flaw in IPv4‑mapped IPv6 detection, but provides no PoC, exploit details, or patch notice.

    0000055
    163 followersView on X
  • The Hacker Wire@TheHackerWire
    General

    🟠 CVE-2026-31943 - High LibreChat is a ChatGPT clone with additional features. Prior to version 0.8.3, `isPrivateIP()` in `packages/api/src/auth/domain.ts` fails to detect IPv4-mapped IPv6 addresses in their hex-nor... https://www.thehackerwire.com/vulnerability/CVE-2026-31943/ https://t.co/ompy8AplAO

    Post summary

    The message announces CVE‑2026‑31943 in LibreChat as a flaw in IPv4‑mapped IPv6 detection, but does not provide PoC, exploit code, or patch information.

    0000050
    163 followersView on X
  • CVEFind.com@CveFindCom
    Patch

    [CVE-2026-31943: HIGH] LibreChat had a cyber security vulnerability in `isPrivateIP()` prior to version 0.8.3, allowing authenticated users to bypass SSRF protection. Upgrade to v0.8.3 to fix it.#cve,CVE-2026-31943,#cybersecurity https://cvefind.com/CVE-2026-31943

    Post summary

    LibreChat’s isPrivateIP() flaw permits authenticated users to bypass SSRF protection; updating to v0.8.3 resolves the issue.

    0000046
    617 followersView on X
CPE platform detail3 entries

3 of 3 entries

PartVendorProductVersionTarget SWTarget HW
Applibrechatlibrechat---
Applibrechatlibrechat0.8.3--
Applibrechatlibrechat0.8.3--

Explore more