vulns.co
/
GKData.io MCP

LibreChat · 1 min read

LibreChat: viewing an integration must not reveal its service secrets

The MCP registry prepared decrypted configuration for internal use, and response handlers returned that representation to viewers without removing secrets. Object visibility consequently became credential disclosure authority. The advisory documents a local demonstration exposing administrator-managed provider credentials to a view-only account.

Open the reference Maintainer AdvisoryReviewed 2026-10-03

How to use this reference

The source recommends secret-free responses and presence indicators. Editorial review principle: define separate execution and presentation representations, then verify that list and detail responses preserve the same field-level disclosure policy.

Before reading

  • Integration credentials, response serialization, and object versus field authorization

Context and limits

  • Requires MCP enabled, stored administrator-managed secrets, and viewer access to the shared integration.
  • CVE-2026-44653: affected v0.8.3 and patched v0.8.4 are listed; patch release date is not established by the advisory. March 13 is the reported test date, not publication.
  • Credential reuse and indirect exposure through shared agents are possible extensions discussed by the source, not demonstrated outcomes. No production compromise or award is established.

Sources and provenance

  1. Shared MCP Server View Leaks Decrypted Admin Secrets LibreChat · reviewed 2026-10-03

Record reviewed 2026-10-03. Snapshot d5550c789111. Open the complete JSON contract.

GitHub snapshot 2026-10-04

d5550c789111 · JSON exports & schemas · CC BY 4.0 content / MIT software