ZeroHour

CVE-2024-10363

PoC
CVSS 3.0
5.4 medium
EPSS
<1%p28
Published
()
Modified
Description

In version 0.7.5 of danny-avila/LibreChat, there is an improper access control vulnerability. Users can share, use, and create prompts without being granted permission by the admin. This can break application logic and permissions, allowing unauthorized actions.

Vendors
librechat
Products
librechat
Weakness
CWE-862
Vector
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N

In the news

No ingested article mentions this CVE yet.