Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Tue, 24 Mar 2026 18:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Librechat
Librechat librechat |
|
| CPEs | cpe:2.3:a:librechat:librechat:0.8.1:rc2:*:*:*:*:*:* | |
| Vendors & Products |
Librechat
Librechat librechat |
Thu, 19 Mar 2026 09:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Danny-avila
Danny-avila libre Chat |
|
| Vendors & Products |
Danny-avila
Danny-avila libre Chat |
Wed, 18 Mar 2026 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 18 Mar 2026 11:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | LibreChat version 0.8.1-rc2 uses the same JWT secret for the user session mechanism and RAG API which compromises the service-level authentication of the RAG API. | |
| Title | LibreChat RAG API Authentication Bypass | |
| Weaknesses | CWE-284 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: sba-research
Published:
Updated: 2026-03-18T14:19:49.089Z
Reserved: 2025-04-16T09:37:50.631Z
Link: CVE-2025-41258
Updated: 2026-03-18T14:19:43.810Z
Status : Analyzed
Published: 2026-03-18T12:16:18.713
Modified: 2026-03-24T18:41:38.697
Link: CVE-2025-41258
No data.
OpenCVE Enrichment
Updated: 2026-03-25T11:52:50Z