PT-2025-31902 · Danny Avila · Librechat

LibreChat is a ChatGPT clone with additional features. In versions 0.0.6 through 0.7.7-rc1, an exposed testing endpoint allows reading arbitrary chats directly from the Meilisearch engine. The endpoin ...

Continue Reading
CVE-2025-54804

creation_timestamp| type| source ---|---|--- 2025-08-05 03:53:50+00:00| seen|...Read More ...

Continue Reading
CVE-2025-54870

creation_timestamp| type| source ---|---|--- 2025-08-05 03:58:50+00:00| seen|...Read More ...

Continue Reading
CVE-2025-54803

creation_timestamp| type| source ---|---|--- 2025-08-05 04:03:51+00:00| seen|...Read More ...

Continue Reading
CVE-2025-54865

creation_timestamp| type| source ---|---|--- 2025-08-05 04:08:51+00:00| seen|...Read More ...

Continue Reading
CVE-2025-8535

creation_timestamp| type| source ---|---|--- 2025-08-05 04:13:52+00:00| seen|...Read More ...

Continue Reading
CVE-2025-8537

creation_timestamp| type| source ---|---|--- 2025-08-05 04:18:53+00:00| seen|...Read More ...

Continue Reading
Lichess: Server-Side Request Forgery (SSRF) via Game Export API

The Lichess game export API was found to be vulnerable to Server-Side Request Forgery (SSRF) due to insufficient input validation of the "players" parameter. This allowed an attacker ...

Continue Reading

Back to Main

Subscribe for the latest news: