/ data / vuln_en / librechat / CVE-2026-33265.yaml
CVE-2026-33265.yaml
 1  info:
 2    name: librechat
 3    cve: CVE-2026-33265
 4    summary: LibreChat v0.8.1-rc2 JWT token exposure
 5    details: >-
 6      In LibreChat 0.8.1-rc2, a logged-in user obtains a JWT for both the LibreChat API and the RAG API.
 7    cvss: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:L
 8    severity: MEDIUM
 9    security_advise: Upgrade to the latest patched version of LibreChat.
10    references:
11      - https://github.com/sbaresearch/advisories/tree/public/2025/SBA-ADV-20251205-01_LibreChat_RAG_API_Authentication_Bypass
12      - https://www.openwall.com/lists/oss-security/2026/03/18/3
13  rule: ""
14  references:
15    - https://github.com/sbaresearch/advisories/tree/public/2025/SBA-ADV-20251205-01_LibreChat_RAG_API_Authentication_Bypass
16    - https://www.openwall.com/lists/oss-security/2026/03/18/3