Description
LibreChat RAG API, version 0.7.0, contains a log-injection vulnerability that allows attackers to forge log entries.
Published: 2026-03-16
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: Log Poisoning
Action: Patch Now
AI Analysis

Impact

LibreChat RAG API version 0.7.0 includes a log‑injection flaw that lets an attacker insert malformed data into log files, creating forged entries that could hide malicious activity or mislead forensics. This ultimately compromises the integrity of audit logs, allowing deception and obfuscation of real events. The weakness is a classic injection vulnerability, as it fails to sanitize user‑supplied input before logging it.

Affected Systems

Systems running LibreChat RAG API 0.7.0 are affected. The vulnerability is specific to this version of the RAG API, so any deployment using this exact release or earlier without the fix is potentially susceptible.

Risk and Exploitability

The CVSS base score of 7.5 indicates a high impact risk. EPSS is below 1%, suggesting the probability of exploitation is currently low, and the issue is not yet in CISA’s KEV catalog. The likely attack vector would be through remote API calls that submit data to the service, given that the vulnerability is triggered via log input. However, this inference comes from the nature of the flaw rather than explicit documentation. If exploited, attackers could tamper with audit trails, undermining incident response.

Generated by OpenCVE AI on March 27, 2026 at 21:57 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade LibreChat RAG API to the latest patched version.
  • Restrict API access to trusted users or IP ranges.
  • Sanitize or escape all data before writing to logs.
  • Enable strict logging controls and alert on suspicious log patterns.
  • Monitor security advisories and apply future updates promptly.

Generated by OpenCVE AI on March 27, 2026 at 21:57 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 29 Mar 2026 20:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-107
CWE-20

Fri, 27 Mar 2026 20:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-107
CWE-15

Fri, 27 Mar 2026 10:00:00 +0000

Type Values Removed Values Added
Weaknesses CWE-107
CWE-15

Fri, 27 Mar 2026 08:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-117

Thu, 26 Mar 2026 12:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-117

Wed, 25 Mar 2026 22:00:00 +0000

Type Values Removed Values Added
Weaknesses CWE-532

Wed, 25 Mar 2026 15:00:00 +0000

Type Values Removed Values Added
Weaknesses CWE-532

Wed, 25 Mar 2026 12:00:00 +0000

Type Values Removed Values Added
Weaknesses CWE-79
CWE-89

Tue, 24 Mar 2026 13:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-79
CWE-89

Tue, 17 Mar 2026 18:15:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 17 Mar 2026 10:00:00 +0000

Type Values Removed Values Added
First Time appeared Librechat
Librechat rag Api
Vendors & Products Librechat
Librechat rag Api

Mon, 16 Mar 2026 17:30:00 +0000

Type Values Removed Values Added
References

Mon, 16 Mar 2026 15:45:00 +0000

Type Values Removed Values Added
Description LibreChat RAG API, version 0.7.0, contains a log-injection vulnerability that allows attackers to forge log entries.
Title LibreChat RAG API, version 0.7.0, contains a log-injection vulnerability that allows attackers to forge log entries.
References

Subscriptions

Librechat Rag Api
cve-icon MITRE

Status: PUBLISHED

Assigner: certcc

Published:

Updated: 2026-03-17T17:15:16.494Z

Reserved: 2026-03-16T15:25:58.025Z

Link: CVE-2026-4276

cve-icon Vulnrichment

Updated: 2026-03-16T16:22:47.436Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-03-16T16:16:18.723

Modified: 2026-03-17T18:16:17.670

Link: CVE-2026-4276

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-03-29T20:29:08Z

Weaknesses