vulns.co
/
GKData.io MCP

LibreChat · 1 min read

LibreChat: agent edit authority must cover attached context

The advisory contrasts denied access to a private agent with accepted changes to its attached files. Upload handling omitted the agent permissions enforced elsewhere, allowing unauthorized context and search-file additions. The documented demonstration changed the owner-visible agent response. This is an application authorization failure before model interpretation.

Open the reference Maintainer AdvisoryReviewed 2026-10-03

How to use this reference

The source recommends checking agent-edit permission for uploads. Editorial review principle: enumerate every mutation of an agent’s effective context, including attachments and retrieval indexes; hiding its configuration does not protect those mutations.

Before reading

  • Object-level authorization and agent context composition

Context and limits

  • The advisory credits Lisa Gnedt and Michael Koppmann of SBA Research, with GitHub Reporter credits for lxp and mkoppmann. It does not display an explicit author byline; these credits alone do not establish advisory authorship, so named authors remain unestablished.
  • Requires an authenticated account and knowledge of another agent’s identifier; private agents were not ordinarily visible.
  • CVE-2025-69220: the advisory identifies 0.8.1-rc2 as affected and records the 0.8.2-rc2 fix release on January 7, 2026.
  • No production compromise, data theft, or award is established. Broader model behavior depends on application context; this review did not run the demonstration.

Sources and provenance

  1. LibreChat Insufficient Access Control on Agent Files LibreChat · reviewed 2026-10-03

Record reviewed 2026-10-03. Snapshot 53796974ace8. Open the complete JSON contract.

GitHub snapshot 2026-10-04

53796974ace8 · JSON exports & schemas · CC BY 4.0 content / MIT software