VYPR
Medium severity6.8NVD Advisory· Published Mar 27, 2026· Updated Jun 17, 2026

CVE-2026-31951

CVE-2026-31951

Description

LibreChat is a ChatGPT clone with additional features. In versions 0.8.2-rc1 through 0.8.3-rc1, user-created MCP (Model Context Protocol) servers can include arbitrary HTTP headers that undergo credential placeholder substitution. An attacker can create a malicious MCP server with headers containing {{LIBRECHAT_OPENID_ACCESS_TOKEN}} (and others), causing victims who call tools on that server to have their OAuth tokens exfiltrated. Version 0.8.3-rc2 fixes the issue.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

4
  • cpe:2.3:a:librechat:librechat:*:*:*:*:*:*:*:*+ 3 more
    • cpe:2.3:a:librechat:librechat:*:*:*:*:*:*:*:*range: >=0.8.2,<0.8.3
    • cpe:2.3:a:librechat:librechat:0.8.3:rc1:*:*:*:*:*:*
    • (no CPE)range: 0.8.2-rc1 - 0.8.3-rc1
    • (no CPE)range: >= v0.8.2-rc1, <= v0.8.3-rc1

Patches

Vulnerability mechanics

References

1

News mentions

0

No linked articles in our index yet.