LibreChat version 0.8.1-rc2 uses the same JWT secret for the user session mechanism and RAG API which compromises the service-level authentication of the RAG API.
Project Subscriptions
No data.
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Wed, 18 Mar 2026 11:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | LibreChat version 0.8.1-rc2 uses the same JWT secret for the user session mechanism and RAG API which compromises the service-level authentication of the RAG API. | |
| Title | LibreChat RAG API Authentication Bypass | |
| Weaknesses | CWE-284 | |
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: sba-research
Published:
Updated: 2026-03-18T11:08:19.866Z
Reserved: 2025-04-16T09:37:50.631Z
Link: CVE-2025-41258
No data.
Status : Received
Published: 2026-03-18T12:16:18.713
Modified: 2026-03-18T12:16:18.713
Link: CVE-2025-41258
No data.
OpenCVE Enrichment
No data.
Weaknesses