LibreChat RAG API Authentication Bypass
Vulnerability Description
LibreChat version 0.8.1-rc2 uses the same JWT secret for the user session mechanism and RAG API which compromises the service-level authentication of the RAG API.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2025-41258
Credits & Attribution
The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:
- Lisa Gnedt (SBA Research)
- Michael Koppmann (SBA Research)
References
More from danny-avila
View All →Affected Vendor
danny-avila
View all reports →