Back to Database
Status published
Medium
CVE-2024-10363
Improper Access Control in danny-avila/LibreChat
Vulnerability Description
In version 0.7.5 of danny-avila/LibreChat, there is an improper access control vulnerability. Users can share, use, and create prompts without being granted permission by the admin. This can break application logic and permissions, allowing unauthorized actions.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2024-10363
Credits & Attribution
No credits recorded in the NVD database.
References
More from danny-avila
View All →CVE-2025-8850
Insecure API Design in danny-avila/librechat
Low
3.1
CVE-2025-8849
Denial of Service in danny-avila/librechat
Medium
5.4
CVE-2025-8848
HTML Injection in Accept-Language Header in danny-avila/librechat
Medium
4.8
CVE-2025-7106
Authorization Bypass due to Incorrect Access Control in danny-avila/librechat
Medium
5.3
CVE-2025-7105
Denial of Service via JavaScript Memory Overflow in danny-avila/librechat
Medium
5.7
Affected Vendor
danny-avila
View all reports →Affected Software
danny-avila/librechat
Vulnerable Versions:
unspecified
Timeline
Official Publish:
March 20th, 2025
Last Modified:
October 15th, 2025
Added to House:
July 22nd, 2026
CVSS Vectors
V3:
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N