LibreChat MCP and Access Control Vulnerabilities (CVE-2026-32625, CVE-2026-44653, CVE-2026-31942): Environment Variable Injection, Permission Bypass, and IDOR
Three vulnerabilities have been disclosed in LibreChat, the open-source ChatGPT clone supporting multiple AI providers, tracked as CVE-2026-32625 (CVSS 9.8 Critical), CVE-2026-44653 (CVSS 7.5 High), … Read More