CVE-2024-11167

An improper access control vulnerability in danny-avila/librechat versions prior to 0.7.6 allows authenticated users to delete other users' prompts via the groupid parameter. This issue occurs because the endpoint does not verify whether the provided prompt ID belongs to the current user.
Configurations

Configuration 1 (hide)

cpe:2.3:a:librechat:librechat:*:*:*:*:*:*:*:*

History

15 Jul 2025, 11:15

Type Values Removed Values Added
CWE CWE-284

14 Jul 2025, 14:11

Type Values Removed Values Added
References () https://github.com/danny-avila/librechat/commit/5071bdbf9ac621165f0e8d009818851f3951eee7 - () https://github.com/danny-avila/librechat/commit/5071bdbf9ac621165f0e8d009818851f3951eee7 - Patch
References () https://huntr.com/bounties/298f5760-5797-4432-8b9e-544609d612c0 - () https://huntr.com/bounties/298f5760-5797-4432-8b9e-544609d612c0 - Exploit, Third Party Advisory
First Time Librechat
Librechat librechat
CWE CWE-639
CPE cpe:2.3:a:librechat:librechat:*:*:*:*:*:*:*:*
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 5.3

20 Mar 2025, 10:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-03-20 10:15

Updated : 2025-07-15 11:15


NVD link : CVE-2024-11167

Mitre link : CVE-2024-11167


JSON object : View

Products Affected

librechat

  • librechat
CWE
CWE-639

Authorization Bypass Through User-Controlled Key