Impact
LibreChat allows authenticated users to configure custom OpenAI-compatible API base URLs without SSRF validation. By setting the baseURL to internal addresses, an attacker can force LibreChat to send HTTP requests to private network hosts, potentially exposing sensitive data or enabling further exploitation.
Affected Systems
The affected vendor is danny-avila, product LibreChat. Versions before 0.8.4-rc1 are vulnerable.
Risk and Exploitability
The CVSS score of 7.7 indicates a high severity. The EPSS score is not available, and the vulnerability is not listed in CISA’s KEV catalog. An attacker needs authentication and permission to edit the baseURL configuration; from that position they can dispatch requests to any target resolved by the baseURL, including private IPs and internal services, as no checks enforce scheme or address restrictions.
OpenCVE Enrichment