Improper access control in LibreChat - CVE-2026-31950
Published: April 27, 2026
LibreChat
Detailed vulnerability description
The vulnerability allows a remote user to disclose sensitive information.
The vulnerability exists due to improper access control in the /api/agents/chat/stream/:streamId endpoint when handling SSE stream subscription requests. A remote user can send a request with a valid stream ID to disclose sensitive information.
Only instances with agents enabled are vulnerable.