Librechat · Librechat · CVE-2026-54030
**Name of the Vulnerable Software and Affected Versions**
LibreChat versions prior to 0.8.5
**Description**
LibreChat is an enhanced ChatGPT clone supporting multiple AI providers. The MCP OAuth implementation fails to validate that the `resource` parameter from OAuth Protected Resource metadata (RFC 9728) matches the configured MCP server URL. This flaw allows a malicious MCP server to steal access tokens intended for a legitimate server.
**Recommendations**
Update to version 0.8.5.