Missing Authorization in LibreChat - CVE-2025-69221

 

Missing Authorization in LibreChat - CVE-2025-69221

Published: April 27, 2026


Vulnerability identifier: #VU128106
CSH Severity: Low
CVSS v4: 5.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2025-69221
CWE-ID: CWE-862
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to disclose sensitive information.

The vulnerability exists due to missing authorization in the agent permission query endpoint when querying agent permissions by agent ID. A remote user can send a crafted request for an arbitrary agent ID to disclose sensitive information.

The exposed data can include individually assigned permissions for other users, and exploitation requires knowledge of the target agent ID.


Affected software

LibreChat

How to mitigate CVE-2025-69221

Install security update from vendor's website.

LibreChat - update to 0.8.2 rc2

External References

Related Security Bulletins