PatchSiren

PatchSiren cyber security CVE debrief

CVE-2025-69222 danny-avila CVE debrief

A critical vulnerability was found in LibreChat version 0.8.1-rc2, allowing for server-side request forgery (SSRF) due to missing restrictions in the Actions feature. This issue enables users to configure agents that can interact with remote services, potentially accessing internal components like the RAG API in the default Docker Compose setup. The vulnerability allows for unauthorized access to internal components, and defenders should verify exposure and prioritize securing these components.

Vendor
danny-avila
Product
LibreChat
CVSS
CRITICAL 9.1
CISA KEV
Not listed in stored evidence
Original CVE published
2026-01-07
Original CVE updated
2026-09-30
Advisory published
2026-01-07
Advisory updated
2026-09-30

Who should care

Defenders managing LibreChat deployments, especially those using the default configuration and Docker Compose setup, should assess exposure and prioritize securing internal components.

Why it matters

CVE-2025-69222 is a critical SSRF vulnerability in LibreChat version 0.8.1-rc2, allowing potential unauthorized access to internal components. Defenders should verify exposure, prioritize securing internal components, and update to version 0.8.2-rc2 or later.

  • Potential unauthorized access to internal components like the RAG API.
  • Possible exploitation of internal services via SSRF.
  • Need for verification of LibreChat version and exposure.
  • Priority on updating to version 0.8.2-rc2 or later.

Technical summary

LibreChat version 0.8.1-rc2 has a critical SSRF vulnerability due to the Actions feature's unrestricted access to remote services. This allows agents to interact with internal components like the RAG API in the default Docker Compose setup. The vulnerability is caused by the lack of restrictions on the Actions feature, enabling users to configure agents that can access internal services. Defenders should assess the security of internal components like the RAG API and prioritize securing them to prevent unauthorized access.

Defensive priority

Defenders should prioritize verifying exposure of LibreChat deployments, especially those using the default Docker Compose setup, and assess the security of internal components like the RAG API.

Recommended defensive actions

  • Verify if LibreChat version 0.8.1-rc2 is in use and assess exposure of internal components like the RAG API.
  • Restrict access to the Actions feature to prevent unauthorized SSRF.
  • Update to version 0.8.2-rc2 or later to apply the fix.
  • Monitor for suspicious activity related to the Actions feature and internal component interactions.
  • Perform an inventory of assets using LibreChat to identify potential targets.
  • Review network configurations to restrict access to internal components.
  • Implement additional monitoring for internal component interactions.

Evidence notes

The vulnerability is confirmed in LibreChat version 0.8.1-rc2. The issue allows for SSRF due to unrestricted Actions feature usage. The default configuration enables access to internal components like the RAG API. The fix is included in version 0.8.2-rc2.

Sources and references

Verified primary and authoritative sources

  • CVE-2025-69222 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2025-69222

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2025-69222 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2025-69222

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.