CVE-2025-41258

LibreChat version 0.8.1-rc2 uses the same JWT secret for the user session mechanism and RAG API which compromises the service-level authentication of the RAG API.
Configurations

Configuration 1 (hide)

cpe:2.3:a:librechat:librechat:0.8.1:rc2:*:*:*:*:*:*

History

No history.

Information

Published : 2026-03-18 12:16

Updated : 2026-03-24 18:41


NVD link : CVE-2025-41258

Mitre link : CVE-2025-41258

CVE.ORG link : CVE-2025-41258


JSON object : View

Products Affected

librechat

  • librechat
CWE
CWE-284

Improper Access Control