Known vulnerabilities in RAG API
Vendor:
LibreChat
Software:
RAG API
Software CPE:
cpe:2.3:a:librechat:rag_api:*:*:*:*:*:librechat:*:*
Website:
https://www.librechat.ai/
Total vulnerabilities:
3
Public exploits:
2
Known exploited (KEV):
0
Highest CVSSv4 Score:
7.2
Breakdown by Severity Chart
Vulnerabilities (3)
| Vulnerability | CWE-ID | CSH Severity | Public Exploit | KEV | First fixed release | Published | Bulletins |
|---|---|---|---|---|---|---|---|
| #VU124047 - Improper Output Neutralization for Logs CVE-2026-4276 |
CWE-117 | Medium | - | 17.03.2026 |
SB2026031703 |
||
| #VU124046 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') CVE-2025-68414 |
CWE-22 | Medium | 0.7.1 | 17.03.2026 |
SB2026031701 |
||
| #VU124045 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') CVE-2025-68413 |
CWE-22 | Medium | 0.7.1 | 17.03.2026 |
SB2026031701 |