Improper access control in LibreChat - CVE-2026-54030

 

Improper access control in LibreChat - CVE-2026-54030

Published: June 3, 2026


Vulnerability identifier: #VU133255
CSH Severity: High
CVSS v4: 7.4 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-54030
CWE-ID: CWE-284
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to disclose sensitive information.

The vulnerability exists due to improper access control in packages/api/src/mcp/oauth/handler.ts when processing OAuth protected resource metadata from an MCP server. A remote attacker can supply crafted metadata with a mismatched resource parameter to disclose sensitive information.

User interaction is required to complete the OAuth flow.


Affected software

LibreChat

How to mitigate CVE-2026-54030

Install security update from vendor's website.

LibreChat - update to 0.8.5

External References

Related Security Bulletins