Floragasse 7 – 5th floor, 1040 Vienna

News

SBA Security Advisory – LibreChat Insufficient Access Control on Agent Permission Queries (CVE-2025-69221)

Vulnerability Overview

LibreChat version 0.8.1-rc2 does not enforce proper access control when querying agent permissions.

  • Type of Vulnerability: Incorrect Access Control
  • Fixed in Version: 0.8.2-rc2
  • CVE ID: CVE-2025-69221
  • CVSS Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
  • CVSS Base Score: 4.3 (Medium)

Recommended Countermeasure

We recommend updating to LibreChat version 0.8.2-rc2 or later.

Links

Full Security Advisory

Credits

Lisa Gnedt (SBA Research)
Michael Koppmann (SBA Research)

The discovery of this vulnerability was made possible through support from CYSSDE and the European Union.