Input validation error in LibreChat - CVE-2026-22252

 

Input validation error in LibreChat - CVE-2026-22252

Published: April 27, 2026


Vulnerability identifier: #VU128105
CSH Severity: Low
CVSS v4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-22252
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to execute arbitrary shell commands as root inside the container.

The vulnerability exists due to improper input validation in the MCP stdio transport when handling crafted API requests for MCP server creation. A remote privileged user can send a specially crafted HTTP request with an arbitrary command to execute arbitrary shell commands as root inside the container.

The issue works on the default installation and is triggered during MCP server creation during inspection.


Affected software

LibreChat

How to mitigate CVE-2026-22252

Install security update from vendor's website.

LibreChat - update to 0.8.2 rc2

External References

Related Security Bulletins