VYPR
High severity7.5NVD Advisory· Published Aug 5, 2025· Updated Jun 17, 2026

CVE-2025-54868

CVE-2025-54868

Description

LibreChat is a ChatGPT clone with additional features. In versions 0.0.6 through 0.7.7-rc1, an exposed testing endpoint allows reading arbitrary chats directly from the Meilisearch engine. The endpoint /api/search/test allows for direct access to stored chats in the Meilisearch engine without proper access control. This results in the ability to read chats from arbitrary users. This issue is fixed in version 0.7.7.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

3
  • Librechat/Librechatv53 versions
    >= 0.0.6, < 0.7.7+ 2 more
    • (no CPE)range: >= 0.0.6, < 0.7.7
    • (no CPE)range: 0.0.6 - 0.7.7-rc1
    • cpe:2.3:a:librechat:librechat:*:*:*:*:*:*:*:*range: >=0.0.6,<0.7.8

Patches

Vulnerability mechanics

References

2

News mentions

0

No linked articles in our index yet.