Filtered by vendor Librechat
Subscribe
Total
2 CVE
CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
---|---|---|---|---|---|
CVE-2024-41703 | 1 Librechat | 1 Librechat | 2024-07-25 | N/A | 9.8 CRITICAL |
LibreChat through 0.7.4-rc1 has incorrect access control for message updates. (Work on a fixed version release has started in PR 3363.) | |||||
CVE-2024-41704 | 1 Librechat | 1 Librechat | 2024-07-25 | N/A | 9.8 CRITICAL |
LibreChat through 0.7.4-rc1 does not validate the normalized pathnames of images. (Work on a fixed version release has started in PR 3363.) |