CVE-2024-41704: Librechat

Critical severity, CVSS 9.8. EPSS: 0.7% chance of exploitation in the next 30 days.

LibreChat through 0.7.4-rc1 does not validate the normalized pathnames of images.

Affected products

  • Librechat Librechat: up to and including 0.7.3; version 0.7.4 only

Published 2024-07-22. Last modified 2026-06-17.