PT-2026-52470 · Librechat · Librechat
CVSS v3.1
8.1
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
LibreChat versions prior to 0.8.4-rc1
Description
An authenticated user or an attacker with a stolen session can access the 'GET /api/auth/2fa/enable' endpoint even if two-factor authentication (2FA) is already active. This action overwrites the current Time-based One-Time Password (TOTP) secret, generates new backup codes, and sets the
twoFactorEnabled variable to false without requiring any verification. Consequently, an attacker with a valid session token can seize control of the 2FA settings and lock the legitimate user out of their account.Recommendations
Update to version 0.8.4-rc1.
Exploit
Fix
Missing Authentication
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Librechat