Critical Vulnerability CVE-2026-32625 Discovered in LibreChat
ID: bb057487-8f56-582f-aeb8-ee19dab840e1
STIX ID: report--bb057487-8f56-582f-aeb8-ee19dab840e1
Feed Name: ThreatCluster
CVE-2026-32625 is a critical information-disclosure vulnerability in LibreChat (≤ 0.8.3) where the Model Context Protocol (MCP) server URL validation resolves ${VAR} placeholders against process.env, allowing an authenticated attacker to exfiltrate sensitive environment variables (e.g., CREDS_KEY, CREDS_IV, JWT_SECRET, MONGO_URI) to an attacker-controlled domain; the flaw has a CVSS of 9.6 and is patched in version 0.8.4-rc1, so immediate upgrade and network monitoring for suspicious outbound requests are recommended.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
