Server-Side Request Forgery (SSRF) in LibreChat - CVE-2026-31945
Published: April 27, 2026
LibreChat
Detailed vulnerability description
The vulnerability allows a remote user to disclose sensitive information from internal resources.
The vulnerability exists due to server-side request forgery (SSRF) in agent actions or MCP when processing user-supplied server URLs that resolve via DNS to private IP addresses. A remote user can supply a crafted domain name that resolves to a private IP address to disclose sensitive information from internal resources.
In cloud environments, exploitation may allow access to instance metadata endpoints.