CVE-2024-11167

An improper access control vulnerability in danny-avila/librechat versions prior to 0.7.6 allows authenticated users to delete other users' prompts via the groupid parameter. This issue occurs because the endpoint does not verify whether the provided prompt ID belongs to the current user.
Configurations

Configuration 1 (hide)

cpe:2.3:a:librechat:librechat:*:*:*:*:*:*:*:*

History

15 Jul 2025, 11:15

Type Values Removed Values Added
CWE CWE-284

14 Jul 2025, 14:11

Type Values Removed Values Added
CVSS v2 : unknown
v3 : 9.4
v2 : unknown
v3 : 5.3
CPE cpe:2.3:a:librechat:librechat:*:*:*:*:*:*:*:*
First Time Librechat
Librechat librechat
CWE CWE-639
Summary
  • (es) Una vulnerabilidad de control de acceso indebido en versiones de danny-avila/librechat anteriores a la 0.7.6 permite a los usuarios autenticados eliminar las solicitudes de otros usuarios mediante el parámetro groupid. Este problema se produce porque el endpoint no verifica si el ID de solicitud proporcionado pertenece al usuario actual.
References () https://github.com/danny-avila/librechat/commit/5071bdbf9ac621165f0e8d009818851f3951eee7 - () https://github.com/danny-avila/librechat/commit/5071bdbf9ac621165f0e8d009818851f3951eee7 - Patch
References () https://huntr.com/bounties/298f5760-5797-4432-8b9e-544609d612c0 - () https://huntr.com/bounties/298f5760-5797-4432-8b9e-544609d612c0 - Exploit, Third Party Advisory

20 Mar 2025, 10:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-03-20 10:15

Updated : 2025-07-15 11:15


NVD link : CVE-2024-11167

Mitre link : CVE-2024-11167

CVE.ORG link : CVE-2024-11167


JSON object : View

Products Affected

librechat

  • librechat
CWE
CWE-639

Authorization Bypass Through User-Controlled Key