VYPR
High severity7.5NVD Advisory· Published Mar 20, 2025· Updated Jun 17, 2026

CVE-2024-11172

CVE-2024-11172

Description

A vulnerability in danny-avila/librechat version git a1647d7 allows an unauthenticated attacker to cause a denial of service by sending a crafted payload to the server. The middleware checkBan is not surrounded by a try-catch block, and an unhandled exception will cause the server to crash. This issue is fixed in version 0.7.6.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

3
  • danny-avila/danny-avila/librechatv5
    Range: unspecified
  • cpe:2.3:a:librechat:librechat:*:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:a:librechat:librechat:*:*:*:*:*:*:*:*range: <0.7.6
    • (no CPE)range: <0.7.6

Patches

Vulnerability mechanics

References

2

News mentions

0

No linked articles in our index yet.