CVEs we hold for Danny-avila
Records whose assigning authority named Danny-avila as the affected vendor. Newest identifiers first, capped at 200.
CVE-2026-54040LibreChat: 2FA Backup Code Regeneration Without OTP Verification Allows 2FA Bypassdanny-avila LibreChat
CVE-2026-54037LibreChat: Incomplete Fix for CVE-2025-7105 — /api/convos/duplicate Lacks Rate Limiting Applied to /api/convos/forkdanny-avila LibreChat
CVE-2026-54036LibreChat: 2FA Re-enrollment Allows Full Account 2FA Takeover Without OTP Verificationdanny-avila LibreChat
CVE-2026-54033LibreChat: SSRF via User-Provided Custom Endpoint baseURL — no private IP validation on user-configured API base URLsdanny-avila LibreChat
CVE-2026-54030LibreChat: Missing Resource Parameter Validation in MCP OAuth Flowdanny-avila LibreChat
CVE-2026-54029LibreChat: IDOR in Message Deletion — Incomplete Fix for CVE-2024-41703 Leaves deleteMessages() Without User Filterdanny-avila LibreChat
CVE-2026-54027LibreChat: Image Upload Route Bypasses Agent Permission Check — Incomplete Fix for File Upload Authorizationdanny-avila LibreChat
CVE-2026-54025LibreChat: Stored XSS via unescaped image alt text in markdown artifact previewdanny-avila LibreChat
CVE-2026-54024LibreChat: Incomplete Fix for CVE-2024-11171 — Conversation Import Multer Instance Missing File Size Limitsdanny-avila LibreChat
CVE-2026-44654LibreChat: Shared-agent editor can globally delete owner's file records — breaks owner's other private agentsdanny-avila LibreChat
CVE-2026-34371LibreChat Affected by Arbitrary File Write via `execute_code` Artifact Filename Traversaldanny-avila LibreChat
CVE-2026-32625LibreChat Exfiltrates Server Secrets via MCP Server URL Injectiondanny-avila LibreChat
CVE-2026-31951LibreChat's MCP Server Header Injection Enables OAuth Token Theftdanny-avila LibreChat
CVE-2026-31950LibreChat's IDOR in SSE Stream Subscription Allows Reading Other Users' Chatsdanny-avila LibreChat
CVE-2026-31949LibreChat Denial of Service (DoS) via Unhandled Exception in DELETE /api/convosdanny-avila LibreChat
CVE-2026-31944LibreChat MCP OAuth callback does not validate browser session — allows token theft via redirect linkdanny-avila LibreChat
CVE-2026-31943LibreChat has SSRF protection bypass via IPv4-mapped IPv6 normalization in isPrivateIPdanny-avila LibreChat
CVE-2026-31942LibreChat has IDOR in API Keys Management that allows any authenticated user to overwrite other users' API keysdanny-avila LibreChat
CVE-2025-7106Authorization Bypass due to Incorrect Access Control in danny-avila/librechatdanny-avila/librechat
CVE-2025-7105Denial of Service via JavaScript Memory Overflow in danny-avila/librechatdanny-avila/librechat
CVE-2025-69222LibreChat is vulnerable to Server-Side Request Forgery due to missing restrictionsdanny-avila LibreChat
CVE-2025-69221LibreChat has Insufficient Access Control for Agent Permission Queriesdanny-avila LibreChat
CVE-2025-66451LibreChat's Improper Input Validation in Prompt Creation API Enables Unauthorized Permission Changesdanny-avila LibreChat
CVE-2025-66450LibreChat JSON Injection in Chat POST Allows Remote Resource Inclusion and PXSS via Image Uploaddanny-avila LibreChat
CVE-2025-66201LibreChat is Vulnerable to Server-Side Request Forgery (SSRF) in Actions Capabilitydanny-avila LibreChat
CVE-2024-11169Unhandled Exception Leading to Server Crash in danny-avila/librechatdanny-avila/librechat
CVE-2024-10361Arbitrary File Deletion via Path Traversal in danny-avila/librechatdanny-avila/librechat
CVE-2024-10359Mass Assignment in Preset Creation Allows User ID Manipulation in danny-avila/librechatdanny-avila/librechat
48 records, read from the index as it stood on 20 Sep 2026. Every row opens the record it names, and every value on that record opens its own receipt.
Everything on this page is free. Public data. Withholding it protects nothing.