CVE-2026-32625
A security flaw in LibreChat allows users to trick the system into sending sensitive environment variables to an external server. This happens when the application processes specific placeholders in a user-provided URL during configuration.
An official fix is available, so this entry is kept for 30 days and then removed automatically.
Who is affected
Users of LibreChat versions up to and including 0.8.3.
Real-world impact
An attacker can steal critical secrets, including database credentials and cryptographic keys, which could lead to a full compromise of the entire LibreChat installation.
Why this severity
This vulnerability is rated critical because it allows an authenticated user to remotely steal highly sensitive system secrets, leading to a total compromise of the application's security and data.
What to do about it
- 01Upgrade LibreChat to version 0.8.4-rc1 or later.
NVD-referenced vendor advisory
Timeline
- Jun 2, 2026 · Jun 2, 2026PublishedDisclosed and added to the National Vulnerability Database.
- Jul 22, 2026 · 13d agoAdvisory updatedThe NVD record was last revised.
- Jul 25, 2026 · 11d agoOfficial fix availableA vendor patch or mitigation now exists — see the remediation steps above.
How it’s attacked
References & advisories
- github.com/danny-avila/LibreChat/secur…exploitmitigationvendor advisory