Improper Authorization in LibreChat - CVE-2025-54868
Published: April 27, 2026
LibreChat
Detailed vulnerability description
The vulnerability allows a remote attacker to disclose sensitive information.
The vulnerability exists due to improper authorization in /api/search/test when handling search requests to the Meilisearch engine. A remote attacker can send a specially crafted request to disclose sensitive information.
If the q parameter is omitted, arbitrary chats may be returned.