CVE Field Guide
About Us
CVE-2026-33265
PUBLISHED
Assigner:
mitre
Reserved:
18.03.2026
Published:
18.03.2026
Updated:
18.03.2026
In LibreChat 0.8.1-rc2, a logged-in user obtains a JWT for both the LibreChat API and the RAG API.
Metrics
CVSS 3.1
CVSS Vector:
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:L
CVSS Score:
6.3
CVSS score
6.3
Attack Vector
Local
Scope
Changed
Attack Complexity
Low
Confidentiality Impact
Low
Privileges Required
Low
Integrity Impact
Low
User Interaction
None
Availability Impact
Low
CVSS 3.1
Product Status
Vendor
LibreChat
Product
LibreChat
Versions
Default:
unknown
Version 0.8.1-rc2 is affected
References
https://github.com/sbaresearch/advisories/tree/public/2025/SBA-ADV-20251205-01_LibreChat_RAG_API_Authentication_Bypass
https://www.openwall.com/lists/oss-security/2026/03/18/3
Problem Types
CWE-669 Incorrect Resource Transfer Between Spheres
CWE