← العودة للجدول
CVE-2026-32625
CVE-2026-32625 — VulnCheck: LibreChat is an enhanced ChatGPT clone that supports multiple AI provi
📅 2026-06-02
🔴 Critical 🔥 No VulnCheck AI Attack AI/LLM CVSS 9.6

📋 الوصف الكامل

LibreChat is an enhanced ChatGPT clone that supports multiple AI providers. In versions up to and including 0.8.3, the Model Context Protocol (MCP) server integration resolves ${VAR} placeholders against the server's process.env during Zod schema validation of user-supplied MCP server URLs. Any authenticated user can create a malicious MCP server configuration with a URL pointing to an attack

💻 الأنظمة المتأثرة

VulnCheck: LibreChat is

⚠️ نوع التهديد

AI Attack

🔗 CVE ID

CVE-2026-32625

📡 المصدر

VulnCheck

✅ الحلول والتخفيف

Update to v0.8.3

🔗 المصدر الأصلي ← 📘 NVD ← ⚡ CISA KEV ←