SBA Security Advisory – LibreChat RAG API Authentication Bypass (CVE-2025-41258)
Vulnerability Overview
LibreChat version 0.8.1-rc2 uses the same JWT secret for the user session mechanism and RAG API which compromises the service-level authentication of the RAG API.
- Type of Vulnerability: Incorrect Access Control
- Fixed in Version: 0.8.2-rc2
- CVE ID: CVE-2025-41258
- CVSS Vector: CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
- CVSS Base Score: 8.0 (High)
Recommended Countermeasure
We are not aware of a fix yet. Please contact the vendor.
Links
Credits
Lisa Gnedt (SBA Research)
Michael Koppmann (SBA Research)
The discovery of this vulnerability was made possible through support from CYSSDE and the European Union.
