Improper access control in LibreChat - CVE-2026-44653
Published: June 3, 2026
LibreChat
Detailed vulnerability description
The vulnerability allows a remote user to disclose sensitive information.
The vulnerability exists due to improper access control in the MCP server configuration API endpoints when handling requests for shared MCP server configurations. A remote user can send a request to the MCP server listing or single-server endpoint to disclose sensitive information.
Exposed plaintext values include admin-managed API keys and OAuth client secrets for shared MCP servers.