Home

Description

LibreChat RAG API, version 0.7.0, contains a log-injection vulnerability that allows attackers to forge log entries.

PUBLISHED Reserved 2026-03-16 | Published 2026-03-16 | Updated 2026-03-17 | Assigner certcc

Problem types

CWE-20 Improper Input Validation

CWE-117 Improper Output Neutralization for Logs

Product status

0.7.0
affected

References

www.kb.cert.org/vuls/id/624941

kb.cert.org/vuls/id/624941

cve.org (CVE-2026-4276)

nvd.nist.gov (CVE-2026-4276)

Download JSON