CVE-2025-7105: Danny-Avila Danny-Avila/librechat
Medium severity, CVSS 5.7. EPSS: 0.3% chance of exploitation in the next 30 days.
A vulnerability in danny-avila/librechat allows attackers to exploit the unrestricted Fork Function in `/api/convos/fork` to fork numerous contents rapidly. If the forked content includes a Mermaid graph with a large number of nodes, it can lead to a JavaScript heap out of memory error upon service restart, causing a denial of service. This issue affects the latest version of the product.
Affected products
- Danny-Avila Danny-Avila/librechat: before v0.7.9 (fixed in v0.7.9)
Published 2026-02-02. Last modified 2026-06-17.