VYPR
Unrated severityNVD Advisory· Published Mar 27, 2026· Updated Mar 31, 2026

LibreChat's MCP Server Header Injection Enables OAuth Token Theft

CVE-2026-31951

Description

LibreChat is a ChatGPT clone with additional features. In versions 0.8.2-rc1 through 0.8.3-rc1, user-created MCP (Model Context Protocol) servers can include arbitrary HTTP headers that undergo credential placeholder substitution. An attacker can create a malicious MCP server with headers containing {{LIBRECHAT_OPENID_ACCESS_TOKEN}} (and others), causing victims who call tools on that server to have their OAuth tokens exfiltrated. Version 0.8.3-rc2 fixes the issue.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

2
  • Librechat/Librechatllm-fuzzy2 versions
    >=0.8.2-rc1, <=0.8.3-rc1+ 1 more
    • (no CPE)range: >=0.8.2-rc1, <=0.8.3-rc1
    • (no CPE)range: >= v0.8.2-rc1, <= v0.8.3-rc1

Patches

Vulnerability mechanics

References

1

News mentions

0

No linked articles in our index yet.