CVE Explorer
CVE-2025-69220
LibreChat is a ChatGPT clone with additional features. Version 0.8.1-rc2 does not enforce proper access control for file uploads to an agents file context and file search. An authenticated attacker with access to the agent ID can change the behavior of arbitrary agents by uploading new files to the file context or file search, even if they have no permissions for this agent. This issue is fixed in version 0.8.2-rc2.
Known exploited
Not asserted
Disputed
No
Stale source
No
Conflicts
1
Preserved source conflicts
No provider value was silently selected as the winner.
cwe · 2 assertions
{"cweId":"CWE-284","description":"CWE-284: Improper Access Control","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:d6b6aca5bff3fcc9b9a1d487540c757043bb4ca648d2efeb5d2188f6ad6e8414 · sha256:9cdf69588c5c8b18… · /containers/cna/problemTypes/1/descriptions/0
{"cweId":"CWE-862","description":"CWE-862: Missing Authorization","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:d6b6aca5bff3fcc9b9a1d487540c757043bb4ca648d2efeb5d2188f6ad6e8414 · sha256:9cdf69588c5c8b18… · /containers/cna/problemTypes/0/descriptions/0
Affected products and versions
1 source assertion{"product":"LibreChat","vendor":"danny-avila","versions":[{"status":"affected","version":">= 0.8.1-rc2, < 0.8.2-rc2"}]}
- cve_program_cvelist_v5affectedurn:baitaphish:normalized-source-record:v2:d6b6aca5bff3fcc9b9a1d487540c757043bb4ca648d2efeb5d2188f6ad6e8414 · sha256:9cdf69588c5c8b18… · /containers/cna/affected/0
Provider-owned CVSS observations
1 source assertion{"metric":{"attackComplexity":"HIGH","attackVector":"NETWORK","availabilityImpact":"LOW","baseScore":7.1,"baseSeverity":"HIGH","confidentialityImpact":"NONE","integrityImpact":"HIGH","privilegesRequired":"LOW","scope":"CHANGED","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:N/I:H/A:L","version":"3.1"},"metric_type":"cvssV3_1"}
- cve_program_cvelist_v5cvssurn:baitaphish:normalized-source-record:v2:d6b6aca5bff3fcc9b9a1d487540c757043bb4ca648d2efeb5d2188f6ad6e8414 · sha256:9cdf69588c5c8b18… · /containers/cna/metrics/0/cvssV3_1
CWE assertions
2 source assertions{"cweId":"CWE-284","description":"CWE-284: Improper Access Control","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:d6b6aca5bff3fcc9b9a1d487540c757043bb4ca648d2efeb5d2188f6ad6e8414 · sha256:9cdf69588c5c8b18… · /containers/cna/problemTypes/1/descriptions/0
{"cweId":"CWE-862","description":"CWE-862: Missing Authorization","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:d6b6aca5bff3fcc9b9a1d487540c757043bb4ca648d2efeb5d2188f6ad6e8414 · sha256:9cdf69588c5c8b18… · /containers/cna/problemTypes/0/descriptions/0
Source references
8 source assertions{"name":"https://cwe.mitre.org/data/definitions/284.html","tags":["x_refsource_MISC"],"url":"https://cwe.mitre.org/data/definitions/284.html"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:d6b6aca5bff3fcc9b9a1d487540c757043bb4ca648d2efeb5d2188f6ad6e8414 · sha256:9cdf69588c5c8b18… · /containers/cna/references/2
{"name":"https://cwe.mitre.org/data/definitions/862.html","tags":["x_refsource_MISC"],"url":"https://cwe.mitre.org/data/definitions/862.html"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:d6b6aca5bff3fcc9b9a1d487540c757043bb4ca648d2efeb5d2188f6ad6e8414 · sha256:9cdf69588c5c8b18… · /containers/cna/references/3
{"name":"https://github.com/danny-avila/LibreChat/commit/4b9c6ab1cb9de626736de700c7981f38be08d237","tags":["x_refsource_MISC"],"url":"https://github.com/danny-avila/LibreChat/commit/4b9c6ab1cb9de626736de700c7981f38be08d237"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:d6b6aca5bff3fcc9b9a1d487540c757043bb4ca648d2efeb5d2188f6ad6e8414 · sha256:9cdf69588c5c8b18… · /containers/cna/references/1
{"name":"https://github.com/danny-avila/LibreChat/releases/tag/v0.8.2-rc2","tags":["x_refsource_MISC"],"url":"https://github.com/danny-avila/LibreChat/releases/tag/v0.8.2-rc2"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:d6b6aca5bff3fcc9b9a1d487540c757043bb4ca648d2efeb5d2188f6ad6e8414 · sha256:9cdf69588c5c8b18… · /containers/cna/references/4
{"name":"https://github.com/danny-avila/LibreChat/security/advisories/GHSA-xcmf-rpmh-hg59","tags":["x_refsource_CONFIRM"],"url":"https://github.com/danny-avila/LibreChat/security/advisories/GHSA-xcmf-rpmh-hg59"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:d6b6aca5bff3fcc9b9a1d487540c757043bb4ca648d2efeb5d2188f6ad6e8414 · sha256:9cdf69588c5c8b18… · /containers/cna/references/0
{"name":"https://owasp.org/Top10/A01_2021-Broken_Access_Control","tags":["x_refsource_MISC"],"url":"https://owasp.org/Top10/A01_2021-Broken_Access_Control"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:d6b6aca5bff3fcc9b9a1d487540c757043bb4ca648d2efeb5d2188f6ad6e8414 · sha256:9cdf69588c5c8b18… · /containers/cna/references/5
{"name":"https://owasp.org/www-project-web-security-testing-guide/v42/4-Web_Application_Security_Testing/05-Authorization_Testing/02-Testing_for_Bypassing_Authorization_Schema.html","tags":["x_refsource_MISC"],"url":"https://owasp.org/www-project-web-security-testing-guide/v42/4-Web_Application_Security_Testing/05-Authorization_Testing/02-Testing_for_Bypassing_Authorization_Schema.html"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:d6b6aca5bff3fcc9b9a1d487540c757043bb4ca648d2efeb5d2188f6ad6e8414 · sha256:9cdf69588c5c8b18… · /containers/cna/references/6
{"name":"https://raw.githubusercontent.com/OWASP/ASVS/v5.0.0/5.0/OWASP_Application_Security_Verification_Standard_5.0.0_en.pdf","tags":["x_refsource_MISC"],"url":"https://raw.githubusercontent.com/OWASP/ASVS/v5.0.0/5.0/OWASP_Application_Security_Verification_Standard_5.0.0_en.pdf"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:d6b6aca5bff3fcc9b9a1d487540c757043bb4ca648d2efeb5d2188f6ad6e8414 · sha256:9cdf69588c5c8b18… · /containers/cna/references/7
Attribution and limitations
- CVE Program CVEList V5: Reproduce the MITRE copyright designation and CVE license in copies. Source →
Provider severity values are preserved separately. Baitaphish does not convert them into a risk rating, infer affected products, or treat EPSS as observed exploitation.