VU#624941: LibreChat RAG API contains a log-injection vulnerability

2026-03-16T20:52:14Z9d617c660a767e9573882c0d0907939b08a210f584741d41285f9c2d6043de61
AV/EDR-evasionCRLFCVE-2026-2256CVE-2026-3059CVE-2026-3060CVE-2026-3989LibreChatMS-AgentNode.jsRAGSGLangTLS-fingerprintingViberantivirus-evasionaudit-logscommand-injectiongraphql-upload-minimallog-injectionmalformed-zipmultipart-formdatapath-traversal-local-write-pyxpdf-pymupdfpickle-deserializationprototype-pollutionremote-code-executionunsafe-deserialization

What happened

This collection of CERT vulnerability notes describes multiple distinct issues across open-source projects and commercial software: a log-injection (CRLF) vulnerability in LibreChat RAG API (v0.7.0) that allows authenticated attackers to forge/manipulate logs; prototype-pollution in graphql-upload-minimal (v1.6.1) enabling global Object.prototype tampering; unsafe pickle deserialization in SGLang leading to unauthenticated remote code execution (CVE-2026-3059, CVE-2026-3060) and an additional pickle-based RCE (CVE-2026-3989); malformed ZIP archive handling that can evade antivirus/EDR scanning

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
certcc_vulnotes
Record identifier
9d617c660a767e9573882c0d0907939b08a210f584741d41285f9c2d6043de61
Enrichment time
2026-03-16T20:52:14Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · VU#624941: LibreChat RAG API contains a log-injection vulnerability · Baitaphish