CVE-2026-31950: medium-severity vulnerability in danny-avila LibreChat
LibreChat's IDOR in SSE Stream Subscription Allows Reading Other Users' Chats
Published
13Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackcvss 5.3epss 0.3%
exploitation probability
0.3%top 81% of all CVEs
observed exploitation
nono source reports it
LibreChat is a ChatGPT clone with additional features. In versions 0.8.2-rc2 through 0.8.2-rc3, the SSE streaming endpoint `/api/agents/chat/stream/:streamId` does not verify that the requesting user owns the stream. Any authenticated user who obtains or guesses a valid stream ID can subscribe and read another user's real-time chat content, including messages, AI responses, and tool invocations. Version 0.8.2 patches the issue.
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N
Affected products
danny-avila · LibreChatRelated CVEs — danny-avila LibreChat
In the same product, most dangerous first.
CVE-2025-69222CRITICALLibreChat is vulnerable to Server-Side Request Forgery due to missing restrictionsEPSS 4.2%CVE-2026-22252CRITICALLibreChat MCP Stdio Remote Command ExecutionEPSS 4.1%CVE-2026-54037MEDIUMLibreChat: Incomplete Fix for CVE-2025-7105 — /api/convos/duplicate Lacks Rate Limiting Applied to /api/convos/forkEPSS 0.5%CVE-2026-31949MEDIUMLibreChat Denial of Service (DoS) via Unhandled Exception in DELETE /api/convosEPSS 0.5%CVE-2025-54868HIGHLibreChat exposes arbitrary chats through Meilisearch engineEPSS 0.4%CVE-2026-54024MEDIUMLibreChat: Incomplete Fix for CVE-2024-11171 — Conversation Import Multer Instance Missing File Size LimitsEPSS 0.4%