VU#624941: LibreChat RAG API contains a log-injection vulnerability
2026-03-16T20:52:14Z•9d617c660a767e9573882c0d0907939b08a210f584741d41285f9c2d6043de61
AV/EDR-evasionCRLFCVE-2026-2256CVE-2026-3059CVE-2026-3060CVE-2026-3989LibreChatMS-AgentNode.jsRAGSGLangTLS-fingerprintingViberantivirus-evasionaudit-logscommand-injectiongraphql-upload-minimallog-injectionmalformed-zipmultipart-formdatapath-traversal-local-write-pyxpdf-pymupdfpickle-deserializationprototype-pollutionremote-code-executionunsafe-deserialization
What happened
This collection of CERT vulnerability notes describes multiple distinct issues across open-source projects and commercial software: a log-injection (CRLF) vulnerability in LibreChat RAG API (v0.7.0) that allows authenticated attackers to forge/manipulate logs; prototype-pollution in graphql-upload-minimal (v1.6.1) enabling global Object.prototype tampering; unsafe pickle deserialization in SGLang leading to unauthenticated remote code execution (CVE-2026-3059, CVE-2026-3060) and an additional pickle-based RCE (CVE-2026-3989); malformed ZIP archive handling that can evade antivirus/EDR scanning
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- certcc_vulnotes
- Record identifier
- 9d617c660a767e9573882c0d0907939b08a210f584741d41285f9c2d6043de61
- Enrichment time
- 2026-03-16T20:52:14Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.