CVE-2024-11167

CVSS 3.0 Score 9.4 of 10 (critical)

Details

Published Mar 20, 2025
CWE ID 284

Summary

CVE-2024-11167 is a newly disclosed access control vulnerability affecting danny-avila/librechat before version 0.7.6. This issue permits authenticated users to delete other users' prompts unintentionally. The flaw resides in an endpoint that fails to validate the prompt ID, allowing any user to delete prompts that do not belong to them, using the groupid parameter. This vulnerability poses a significant risk to the security and integrity of chat data within the affected systems. Users are advised to update to the latest version of librechat to mitigate this issue.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share