CVE-2026-54033: Librechat

Medium severity, CVSS 6.5. EPSS: 0.4% chance of exploitation in the next 30 days.

LibreChat is an enhanced ChatGPT clone that supports multiple AI providers. Prior to 0.8.4-rc1, LibreChat allows users to configure custom OpenAI-compatible API endpoints by setting a baseURL. This URL is used to construct HTTP requests without any SSRF validation — no private IP check, no scheme restriction, no DNS pinning. An authenticated user can set baseURL to internal network addresses. This vulnerability is fixed in 0.8.4-rc1.

Affected products

  • Librechat Librechat: up to and including 0.8.3

Published 2026-06-25. Last modified 2026-06-29.