Server-Side Request Forgery (SSRF) in LibreChat - CVE-2025-66201

 

Server-Side Request Forgery (SSRF) in LibreChat - CVE-2025-66201

Published: April 27, 2026


Vulnerability identifier: #VU128112
CSH Severity: Medium
CVSS v4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2025-66201
CWE-ID: CWE-918
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to access internal or arbitrary network resources and disclose sensitive information.

The vulnerability exists due to server-side request forgery in the Actions feature when processing specially crafted OpenAPI specifications. A remote user can submit a crafted action definition with a mismatched allowed domain and server URL to access internal or arbitrary network resources and disclose sensitive information.

Exploitation requires access to the Actions feature.


Affected software

LibreChat

How to mitigate CVE-2025-66201

Install security update from vendor's website.

LibreChat - update to 0.8.1 rc2

External References

Related Security Bulletins