CVE-2024-11169

An unhandled exception in danny-avila/librechat version 3c94ff2 can lead to a server crash. The issue occurs when the fs module throws an exception while handling file uploads. An unauthenticated user can trigger this exception by sending a specially crafted request, causing the server to crash. The vulnerability is fixed in version 0.7.6.
CVSS

No CVSS.

Configurations

Configuration 1 (hide)

cpe:2.3:a:librechat:librechat:*:*:*:*:*:*:*:*

History

15 Jul 2025, 16:45

Type Values Removed Values Added
CPE cpe:2.3:a:librechat:librechat:*:*:*:*:*:*:*:*
First Time Librechat
Librechat librechat
References () https://github.com/danny-avila/librechat/commit/629be5c0ca2b332178524b4e3f6fac715aea8cc4 - () https://github.com/danny-avila/librechat/commit/629be5c0ca2b332178524b4e3f6fac715aea8cc4 - Patch
References () https://huntr.com/bounties/754e1649-5612-4ba9-a533-06b46de5c4b5 - () https://huntr.com/bounties/754e1649-5612-4ba9-a533-06b46de5c4b5 - Exploit, Third Party Advisory

20 Mar 2025, 10:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-03-20 10:15

Updated : 2025-07-15 16:45


NVD link : CVE-2024-11169

Mitre link : CVE-2024-11169


JSON object : View

Products Affected

librechat

  • librechat
CWE
CWE-115

Misinterpretation of Input