Medium severity5.3NVD Advisory· Published Mar 20, 2025· Updated Jun 17, 2026
CVE-2024-11167
CVE-2024-11167
Description
An improper access control vulnerability in danny-avila/librechat versions prior to 0.7.6 allows authenticated users to delete other users' prompts via the groupid parameter. This issue occurs because the endpoint does not verify whether the provided prompt ID belongs to the current user.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3- danny-avila/danny-avila/librechatv5Range: unspecified
Patches
Vulnerability mechanics
References
2- github.com/danny-avila/librechat/commit/5071bdbf9ac621165f0e8d009818851f3951eee7nvdPatch
- huntr.com/bounties/298f5760-5797-4432-8b9e-544609d612c0nvdExploitThird Party Advisory
News mentions
0No linked articles in our index yet.