An improper access control vulnerability in danny-avila/librechat versions prior to 0.7.6 allows authenticated users to delete other users' prompts via the groupid parameter. This issue occurs because the endpoint does not verify whether the provided prompt ID belongs to the current user.
Metrics
Affected Vendors & Products
References
History
Thu, 20 Mar 2025 19:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Thu, 20 Mar 2025 10:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | An improper access control vulnerability in danny-avila/librechat versions prior to 0.7.6 allows authenticated users to delete other users' prompts via the groupid parameter. This issue occurs because the endpoint does not verify whether the provided prompt ID belongs to the current user. | |
Title | Improper Access Control in danny-avila/librechat | |
Weaknesses | CWE-284 | |
References |
| |
Metrics |
cvssV3_0
|

Status: PUBLISHED
Assigner: @huntr_ai
Published:
Updated: 2025-03-20T18:34:15.932Z
Reserved: 2024-11-12T21:07:31.363Z
Link: CVE-2024-11167

Updated: 2025-03-20T17:52:52.516Z

Status : Received
Published: 2025-03-20T10:15:24.097
Modified: 2025-03-20T10:15:24.097
Link: CVE-2024-11167

No data.