Server-Side Request Forgery (SSRF) in LibreChat - CVE-2025-66201
Published: April 27, 2026
LibreChat
Detailed vulnerability description
The vulnerability allows a remote user to access internal or arbitrary network resources and disclose sensitive information.
The vulnerability exists due to server-side request forgery in the Actions feature when processing specially crafted OpenAPI specifications. A remote user can submit a crafted action definition with a mismatched allowed domain and server URL to access internal or arbitrary network resources and disclose sensitive information.
Exploitation requires access to the Actions feature.