CVE-2024-10366

An improper access control vulnerability (IDOR) exists in the delete attachments functionality of danny-avila/librechat version v0.7.5-rc2. The endpoint does not verify whether the provided attachment ID belongs to the current user, allowing any authenticated user to delete attachments of other users.
Configurations

Configuration 1 (hide)

cpe:2.3:a:librechat:librechat:0.7.5:rc2:*:*:*:*:*:*

History

15 Jul 2025, 11:15

Type Values Removed Values Added
CWE CWE-284

14 Jul 2025, 14:32

Type Values Removed Values Added
CWE CWE-639

14 Jul 2025, 14:06

Type Values Removed Values Added
Summary
  • (es) Existe una vulnerabilidad de control de acceso indebido (IDOR) en la función de eliminación de adjuntos de la versión v0.7.5-rc2 de danny-avila/librechat. El endpoint no verifica si el ID del adjunto proporcionado pertenece al usuario actual, lo que permite que cualquier usuario autenticado elimine los adjuntos de otros usuarios.
First Time Librechat
Librechat librechat
CPE cpe:2.3:a:librechat:librechat:0.7.5:rc2:*:*:*:*:*:*
References () https://github.com/danny-avila/librechat/commit/a350443661d001ac55787741969a75d94ca14116 - () https://github.com/danny-avila/librechat/commit/a350443661d001ac55787741969a75d94ca14116 - Patch
References () https://huntr.com/bounties/cde47cf8-dc81-46ab-b472-f7e44a981a7e - () https://huntr.com/bounties/cde47cf8-dc81-46ab-b472-f7e44a981a7e - Exploit, Third Party Advisory
CVSS v2 : unknown
v3 : 7.6
v2 : unknown
v3 : 6.5

20 Mar 2025, 10:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-03-20 10:15

Updated : 2025-07-15 11:15


NVD link : CVE-2024-10366

Mitre link : CVE-2024-10366

CVE.ORG link : CVE-2024-10366


JSON object : View

Products Affected

librechat

  • librechat
CWE
CWE-639

Authorization Bypass Through User-Controlled Key