Input validation error in LibreChat - CVE-2025-66450
Published: April 27, 2026
LibreChat
Detailed vulnerability description
The vulnerability allows a remote user to disclose sensitive information.
The vulnerability exists due to improper input validation in the chat POST handler when processing the user-supplied iconURL parameter. A remote user can send a specially crafted request to disclose sensitive information.
User interaction is required because another user must view a shared chat containing the malicious resource reference.