Impact
LibreChat up to version 0.8.3 allows authenticated users to inject environment variables into MCP server URLs during Zod schema validation, leading to exfiltration of CREDS_KEY, CREDS_IV, JWT_SECRET, and MONGO_URI. This results in full compromise of cryptographic material and database credentials without needing administrative rights.
Affected Systems
The vulnerability affects the LibreChat platform provided by danny-avila. Users running version 0.8.3 or earlier are impacted; the fix is in 0.8.4-rc1.
Risk and Exploitability
The CVSS score is 9.6 indicating high severity. The EPSS score is not available, and the vulnerability is not listed in KEV, but this does not negate the risk. Attackers can exploit the flaw by configuring a malicious MCP server URL that references environment variables, causing the LibreChat server to make outbound HTTP requests to a controlled domain and capture credential data. No privilege escalation is required; any authenticated user can create such a configuration.
OpenCVE Enrichment