Medium severity6.3NVD Advisory· Published Mar 18, 2026· Updated Jun 17, 2026
CVE-2026-33265
CVE-2026-33265
Description
In LibreChat 0.8.1-rc2, a logged-in user obtains a JWT for both the LibreChat API and the RAG API.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3Patches
Vulnerability mechanics
References
2- github.com/sbaresearch/advisories/tree/public/2025/SBA-ADV-20251205-01_LibreChat_RAG_API_Authentication_BypassnvdExploitThird Party Advisory
- www.openwall.com/lists/oss-security/2026/03/18/3nvdExploitMailing ListThird Party Advisory
News mentions
0No linked articles in our index yet.