« Volver al listado

CVE-2026-44653

Estado: AnalizadaMedia (6.5)—

LibreChat is an enhanced ChatGPT clone that supports multiple AI providers. In versions up to and including 0.8.3, users with only `VIEW` access to an MCP server can retrieve the server's decrypted admin-managed secrets through `GET /api/mcp/servers` and `GET /api/mcp/servers/:serverName`. The returned config includes plaintext values for `apiKey.key` and `oauth.client_secret`. This allows viewers of a shared MCP server to exfiltrate the underlying provider credentials. Version 0.8..4 contains a patch.

Leer descripción completaMostrar menos

Other remediations include: never returning decrypted admin-managed secrets to non-owners; redacting apiKey.key and oauth.client_secret from all API responses consider returning only boolean presence indicators for secrets, similar to the auth-values route pattern; and, if owners need to edit configs without re-entering secrets, preserving secrets server-side and returning placeholders instead of plaintext.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2026-44653",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2026-44653",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "poc"
            },
            {
              "automatable": "no"
            },
            {
              "technicalImpact": "partial"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2026-06-03T18:56:30.034562Z"
        }
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "security-advisories@github.com",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 6.5,
          "attackVector": "NETWORK",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N",
          "integrityImpact": "NONE",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "NONE",
          "privilegesRequired": "LOW",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 3.6,
        "exploitabilityScore": 2.8
      }
    ]
  },
  "affected": [
    {
      "source": "security-advisories@github.com",
      "affectedData": [
        {
          "vendor": "danny-avila",
          "product": "LibreChat",
          "versions": [
            {
              "status": "affected",
              "version": "< 0.8.4"
            }
          ]
        }
      ]
    }
  ],
  "published": "2026-06-02T23:16:38.123",
  "references": [
    {
      "url": "https://github.com/danny-avila/LibreChat/security/advisories/GHSA-6vqg-rgpm-qvf9",
      "tags": [
        "Exploit",
        "Mitigation",
        "Vendor Advisory"
      ],
      "source": "security-advisories@github.com"
    },
    {
      "url": "https://github.com/danny-avila/LibreChat/security/advisories/GHSA-6vqg-rgpm-qvf9",
      "tags": [
        "Exploit",
        "Mitigation",
        "Vendor Advisory"
      ],
      "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0"
    }
  ],
  "vulnStatus": "Analyzed",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "security-advisories@github.com",
      "description": [
        {
          "lang": "en",
          "value": "CWE-201"
        }
      ]
    },
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "NVD-CWE-noinfo"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "LibreChat is an enhanced ChatGPT clone that supports multiple AI providers. In versions up to and including 0.8.3, users with only `VIEW` access to an MCP server can retrieve the server's decrypted admin-managed secrets through `GET /api/mcp/servers` and `GET /api/mcp/servers/:serverName`. The returned config includes plaintext values for `apiKey.key` and `oauth.client_secret`. This allows viewers of a shared MCP server to exfiltrate the underlying provider credentials. Version 0.8..4 contains a patch. Other remediations include: never returning decrypted admin-managed secrets to non-owners; redacting apiKey.key and oauth.client_secret from all API responses consider returning only boolean presence indicators for secrets, similar to the auth-values route pattern; and, if owners need to edit configs without re-entering secrets, preserving secrets server-side and returning placeholders instead of plaintext."
    },
    {
      "lang": "es",
      "value": "LibreChat es un clon mejorado de ChatGPT que soporta múltiples proveedores de IA. En versiones hasta la 0.8.3 inclusive, los usuarios con acceso solo de 'VIEW' a un servidor MCP pueden recuperar los secretos descifrados administrados por el administrador del servidor a través de 'GET /api/mcp/servers' y 'GET /api/mcp/servers/:serverName'. La configuración devuelta incluye valores en texto plano para 'apiKey.key' y 'oauth.client_secret'. Esto permite a los espectadores de un servidor MCP compartido exfiltrar las credenciales del proveedor subyacente. La versión 0.8..4 contiene un parche. Otras soluciones incluyen: nunca devolver secretos descifrados administrados por el administrador a no propietarios; redactar 'apiKey.key' y 'oauth.client_secret' de todas las respuestas de la API; considerar devolver solo indicadores de presencia booleanos para los secretos, similar al patrón de ruta de valores de autenticación; y, si los propietarios necesitan editar configuraciones sin volver a introducir secretos, preservar los secretos en el lado del servidor y devolver marcadores de posición en lugar de texto plano."
    }
  ],
  "lastModified": "2026-07-21T19:10:00.107",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:librechat:librechat:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "63FE1740-F55B-4D56-92E5-407F97DA3475",
              "versionEndExcluding": "0.8.4"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "security-advisories@github.com"
}