
CVE-2026-33265 In LibreChat 0.8.1-rc2, a logged-in user obtains a JWT for both the LibreChat API and the RAG API. https://www.cve.org/CVERecord?id=CVE-2026-33265
Post summary
The post announces that in LibreChat 0.8.1‑rc2 a logged‑in user can retrieve JWTs for both the LibreChat and RAG APIs, constituting a token theft vulnerability.


