CVE-2024-11167
CVSS 3.0 Score 9.4 of 10 (critical)
Details
Summary
CVE-2024-11167 is a newly disclosed access control vulnerability affecting danny-avila/librechat before version 0.7.6. This issue permits authenticated users to delete other users' prompts unintentionally. The flaw resides in an endpoint that fails to validate the prompt ID, allowing any user to delete prompts that do not belong to them, using the groupid parameter. This vulnerability poses a significant risk to the security and integrity of chat data within the affected systems. Users are advised to update to the latest version of librechat to mitigate this issue.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.