VU#624941: LibreChat RAG API contains a log-injection vulnerability

2026-03-19T20:52:14Za30fa74b262d74dfaab1ed2886485ae497c8caebdfa6575ca4c5c5faf6589b84
CRLFCVE-2026-2256CVE-2026-3059CVE-2026-3060CVE-2026-3989LibreChatMS-AgentNode.jsPyMuPDFRAG APISGLangZIP obfuscation (retracted)__proto__arbitrary file writecommand injectiongraphql-upload-minimallog-injectionloggingms-agentmultipartpath traversalpickleprototype pollutionremote code executionunsafe deserialization

What happened

This collection of CERT/CC vulnerability notes (Mar 2026) describes multiple distinct vulnerabilities across open-source and commercial software: a CRLF log-injection in LibreChat RAG API (v0.7.0) allowing forged log entries and possible downstream XSS/command execution via insecure log tools; prototype-pollution in graphql-upload-minimal (v1.6.1) enabling Object.prototype pollution across a Node.js process; multiple unsafe Python pickle-deserialization flaws in SGLang (CVE-2026-3059, CVE-2026-3060) and a related replay-tool issue (CVE-2026-3989) enabling unauthenticated remote code execution;

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
certcc_vulnotes
Record identifier
a30fa74b262d74dfaab1ed2886485ae497c8caebdfa6575ca4c5c5faf6589b84
Enrichment time
2026-03-19T20:52:14Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.