Improper access control in LibreChat - #VU133255

 

Improper access control in LibreChat - #VU133255

Published: June 3, 2026


Vulnerability identifier: #VU133255
CSH Severity: High
CVSS v4.0: CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:U/U:Amber
CVE-ID: N/A
CWE-ID: CWE-284
Exploitation vector: Remote access
Exploit availability: No public exploit available
Vendor: LibreChat
Affected software:
LibreChat

Detailed vulnerability description

The vulnerability allows a remote attacker to disclose sensitive information.

The vulnerability exists due to improper access control in packages/api/src/mcp/oauth/handler.ts when processing OAuth protected resource metadata from an MCP server. A remote attacker can supply crafted metadata with a mismatched resource parameter to disclose sensitive information.

User interaction is required to complete the OAuth flow.


Remediation

Install security update from vendor's website.

Sources