Skip to content
CVE-2026-32625 - Exploits & Severity

CVE-2026-32625 - Exploits & Severity

Feedly June 3, 2026

LibreChat is an enhanced ChatGPT clone that supports multiple AI providers. In versions up to and including 0.8.3, the Model Context Protocol (MCP) server integration resolves ${VAR} placeholders against the server's process.env during Zod schema validation of user-supplied MCP server URLs. Any authenticated user can create a malicious MCP server configuration with a URL pointing to an attacker-controlled domain containing environment variable references, causing the LibreChat server to connect to the attacker's server and transmit critical secrets such as CREDS_KEY, CREDS_IV, JWT_SECRET, and MONGO_URI in the request URL. This enables full compromise of the installation's cryptographic materials and database credentials without requiring administrative privileges. This is patched in version 0.8.4-rc1.

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N

NVD published the first details for CVE-2026-32625

A CVSS base score of 9.6 has been assigned.

Feedly found the first article mentioning CVE-2026-32625 . See article

A critical information disclosure vulnerability with a CVSS score of 9.6 allows authenticated users of LibreChat to extract sensitive secrets, such as cryptographic keys and database credentials, by configuring malicious MCP server URLs. There are currently no public proof-of-concept exploits available, but the vulnerability is patched in version 0.8.4-rc1, and upgrading to this version or newer is recommended for mitigation. The flaw affects all versions up to and including 0.8.3, posing significant risks to installations running these vulnerable versions. See article

LibreChat Critical Credential Disclosure via MCP Server URL

Why the browser is now the front line for AI security

LibreChat Critical Credential Disclosure via MCP Server URL

Collect, analyze, and vulnerability reports faster using AI

Extracted Entities