An improper access control vulnerability (IDOR) exists in the delete attachments functionality of danny-avila/librechat version v0.7.5-rc2. The endpoint does not verify whether the provided attachment ID belongs to the current user, allowing any authenticated user to delete attachments of other users.
References
Link | Resource |
---|---|
https://github.com/danny-avila/librechat/commit/a350443661d001ac55787741969a75d94ca14116 | Patch |
https://huntr.com/bounties/cde47cf8-dc81-46ab-b472-f7e44a981a7e | Exploit Third Party Advisory |
Configurations
History
15 Jul 2025, 11:15
Type | Values Removed | Values Added |
---|---|---|
CWE |
14 Jul 2025, 14:32
Type | Values Removed | Values Added |
---|---|---|
CWE | CWE-639 |
14 Jul 2025, 14:06
Type | Values Removed | Values Added |
---|---|---|
References | () https://github.com/danny-avila/librechat/commit/a350443661d001ac55787741969a75d94ca14116 - Patch | |
References | () https://huntr.com/bounties/cde47cf8-dc81-46ab-b472-f7e44a981a7e - Exploit, Third Party Advisory | |
Summary |
|
|
CPE | cpe:2.3:a:librechat:librechat:0.7.5:rc2:*:*:*:*:*:* | |
First Time |
Librechat
Librechat librechat |
|
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 6.5 |
20 Mar 2025, 10:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2025-03-20 10:15
Updated : 2025-07-15 11:15
NVD link : CVE-2024-10366
Mitre link : CVE-2024-10366
CVE.ORG link : CVE-2024-10366
JSON object : View
Products Affected
librechat
- librechat
CWE
CWE-639
Authorization Bypass Through User-Controlled Key