SBA Security Advisory – LibreChat Insufficient Access Control on Agent Permission Queries (CVE-2025-69221)
Vulnerability Overview
LibreChat version 0.8.1-rc2 does not enforce proper access control when querying agent permissions.
- Type of Vulnerability: Incorrect Access Control
- Fixed in Version: 0.8.2-rc2
- CVE ID: CVE-2025-69221
- CVSS Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
- CVSS Base Score: 4.3 (Medium)
Recommended Countermeasure
We recommend updating to LibreChat version 0.8.2-rc2 or later.
Links
Credits
Lisa Gnedt (SBA Research)
Michael Koppmann (SBA Research)
The discovery of this vulnerability was made possible through support from CYSSDE and the European Union.
