CVE-2026-31949 PUBLISHED

LibreChat Denial of Service (DoS) via Unhandled Exception in DELETE /api/convos

Assigner: GitHub_M
Reserved: 10.03.2026 Published: 13.03.2026 Updated: 13.03.2026

LibreChat is a ChatGPT clone with additional features. Prior to 0.8.3-rc1, a Denial of Service (DoS) vulnerability exists in the DELETE /api/convos endpoint that allows an authenticated attacker to crash the Node.js server process by sending malformed requests. The DELETE /api/convos route handler attempts to destructure req.body.arg without validating that it exists. The server crashes due to an unhandled TypeError that bypasses Express error handling middleware and triggers process.exit(1). This vulnerability is fixed in 0.8.3-rc1.

Metrics

CVSS Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
CVSS Score: 6.5

Product Status

Vendor danny-avila
Product LibreChat
Versions
  • Version < 0.8.3-rc1 is affected

References

Problem Types

  • CWE-248: Uncaught Exception CWE