CVE-2024-10363

CVSS 3.0 Score 5.4 of 10 (medium)

Details

Published Mar 20, 2025
CWE ID 284

Summary

CVE-2024-10363 is a vulnerability affecting version 0.7.5 of LibreChat, a software package created by danny-avila. This issue involves a lack of proper access control, enabling users to share, use, and generate prompts without the necessary administrative permissions. Consequently, application logic and permission structures can be bypassed, leading to unauthorized actions. This vulnerability poses a significant security risk and should be addressed promptly by system administrators. Users are advised to upgrade to the latest version of LibreChat as soon as possible to mitigate this issue.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share