SBA Security Advisory – LibreChat Insufficient Access Control on Agent Files (CVE-2025-69220)
Vulnerability Overview
LibreChat version 0.8.1-rc2 does not enforce proper access control for file uploads to an agents file context and file search.
- Type of Vulnerability: Incorrect Access Control
- Fixed in Version: 0.8.2-rc2
- CVE ID: CVE-2025-69220
- CVSS Vector: CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:N/I:H/A:L
- CVSS Base Score: 7.1 (High)
Recommended Countermeasure
We recommend updating to LibreChat version 0.8.2-rc2 or later.
Links
Credits
Lisa Gnedt (SBA Research)
Michael Koppmann (SBA Research)
The discovery of this vulnerability was made possible through support from CYSSDE and the European Union.
