PT-2025-39160 · Librechat · Librechat

CVE-2025-7106

·

Published

2025-09-23

·

Updated

2025-09-23

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions librechat versions prior to the fix
Description An authorization bypass exists due to incorrect access control checks. The checkAccess function within api/server/middleware/roles/access.js utilizes permissions.some() for permission validation, which incorrectly grants access when only one of several required permissions is present. This allows users with the 'USER' role to perform actions, such as creating agents, even if they lack specific permissions like CREATE: false. The issue impacts other permission checks, including those for PROMPTS. The vulnerable function is checkAccess. The vulnerable parameter is permissions.
Recommendations Update to a version of librechat that addresses this authorization bypass.

Exploit

Fix

Improper Access Control

IDOR

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-7106

Affected Products

Librechat