Database/AI/ML frameworks & serving
LibreChat: agent Actions have no destination restrictions by default, reaching internal services via SSRF
Impact
LibreChat lets users give an agent actions that call remote services from an OpenAPI spec, with arbitrary methods, parameters and custom headers. In the default configuration nothing limits which destinations are reachable, so a user-authored agent makes requests from the LibreChat server to anything that server can route to - the advisory names the RAG API that ships in the same default Docker Compose stack. On a GPU fleet the LibreChat pod usually sits inside the cluster network alongside inference endpoints, vector stores, the metadata service and internal admin APIs that assume network-level trust, and this turns any chat user into a client of those. The attacker-controlled headers matter too: the SSRF carries authentication the target may accept.
Who can reach it
Network, authenticated as an ordinary LibreChat user with permission to configure an agent and its actions - no admin role. The reachable targets are whatever the LibreChat server itself can reach, which on an in-cluster deployment includes services never exposed externally.
What to do
Upgrade to the fixed release (the advisory names 0.8.1-rc2 as the fix and links the 0.8.2-rc2 tag; verify against GHSA-rgjq-4q58-m3q8 before you pin a version) and restart the LibreChat container - no node drain, no GPU interruption. Independently of the version, treat this as a network-policy problem: give the LibreChat pod an egress policy that denies cluster-internal and link-local ranges except the services it genuinely needs, since the Actions feature is designed to make outbound calls.
References
Related entries
- picklescan: Misses `idlelib.pyshell.ModifiedInterpreter.runcode` gadgetCVE-2025-71340 · picklescanHigh
- picklescan: Misses `idlelib.run.Executive.runcode` gadgetCVE-2025-71342 · picklescanHigh
- JupyterLab: pasted cell keeps metadata.trusted, running script in the authenticated originCVE-2026-102831 · JupyterLab / Jupyter Notebook / JupyterLite (system-clipboard cell paste)High
- Keras (archive extraction utils): Path traversal in `keras/src/utils/file_utils.py`CVE-2026-11816 · Keras (archive extraction utils)High
- llama-server (KV cache state restore): Heap buffer overflow in `state_read_data`CVE-2026-43629 · llama-server (KV cache state restore)High
- llama-server (tokenization endpoints): Use-after-free across six tokenization endpointsCVE-2026-43632 · llama-server (tokenization endpoints)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.