VU#624941: LibreChat RAG API contains a log-injection vulnerability
2026-03-19T20:52:14Z•a30fa74b262d74dfaab1ed2886485ae497c8caebdfa6575ca4c5c5faf6589b84
CRLFCVE-2026-2256CVE-2026-3059CVE-2026-3060CVE-2026-3989LibreChatMS-AgentNode.jsPyMuPDFRAG APISGLangZIP obfuscation (retracted)__proto__arbitrary file writecommand injectiongraphql-upload-minimallog-injectionloggingms-agentmultipartpath traversalpickleprototype pollutionremote code executionunsafe deserialization
What happened
This collection of CERT/CC vulnerability notes (Mar 2026) describes multiple distinct vulnerabilities across open-source and commercial software: a CRLF log-injection in LibreChat RAG API (v0.7.0) allowing forged log entries and possible downstream XSS/command execution via insecure log tools; prototype-pollution in graphql-upload-minimal (v1.6.1) enabling Object.prototype pollution across a Node.js process; multiple unsafe Python pickle-deserialization flaws in SGLang (CVE-2026-3059, CVE-2026-3060) and a related replay-tool issue (CVE-2026-3989) enabling unauthenticated remote code execution;
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- certcc_vulnotes
- Record identifier
- a30fa74b262d74dfaab1ed2886485ae497c8caebdfa6575ca4c5c5faf6589b84
- Enrichment time
- 2026-03-19T20:52:14Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.