A vulnerability in danny-avila/librechat version git 81f2936 allows for path traversal due to improper sanitization of file paths by the multer middleware. This can lead to arbitrary file write and potentially remote code execution. The issue is fixed in version 0.7.6.
Metrics
Affected Vendors & Products
References
History
Wed, 16 Jul 2025 13:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
epss
|
epss
|
Tue, 15 Jul 2025 17:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Librechat
Librechat librechat |
|
CPEs | cpe:2.3:a:librechat:librechat:*:*:*:*:*:*:*:* | |
Vendors & Products |
Librechat
Librechat librechat |
Thu, 20 Mar 2025 19:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Thu, 20 Mar 2025 10:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | A vulnerability in danny-avila/librechat version git 81f2936 allows for path traversal due to improper sanitization of file paths by the multer middleware. This can lead to arbitrary file write and potentially remote code execution. The issue is fixed in version 0.7.6. | |
Title | Path Traversal in danny-avila/librechat | |
Weaknesses | CWE-29 | |
References |
| |
Metrics |
cvssV3_0
|

Status: PUBLISHED
Assigner: @huntr_ai
Published: 2025-03-20T10:08:59.584Z
Updated: 2025-03-20T18:59:47.731Z
Reserved: 2024-11-12T21:32:48.240Z
Link: CVE-2024-11170

Updated: 2025-03-20T17:50:46.235Z

Status : Analyzed
Published: 2025-03-20T10:15:24.323
Modified: 2025-07-15T16:45:15.543
Link: CVE-2024-11170

No data.