CVE-2025-41258
EUVD-2025-20882518.03.2026, 12:16
LibreChat version 0.8.1-rc2 uses the same JWT secret for the user session mechanism and RAG API which compromises the service-level authentication of the RAG API.Enginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| librechat | librechat | 0.8.1:rc2 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration