← Back

CVE-2024-10361

nvd nist
Published: Mar 20, 2025Modified: Oct 15, 2025

JSON object

Loading...
9.1
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H
Exploitability: 3.9 / Impact: 5.2
Source: NVD

Description

An arbitrary file deletion vulnerability exists in danny-avila/librechat version v0.7.5-rc2, specifically within the /api/files endpoint. This vulnerability arises from improper input validation, allowing path traversal techniques to delete arbitrary files on the server. Attackers can exploit this to bypass security mechanisms and delete files outside the intended directory, including critical system files, user data, or application resources. This vulnerability impacts the integrity and availability of the system.

Affected (1)

Products: Librechat: Librechat
1 product
Librechat
Configuration A
1 vulnerable
Vulnerable SoftwareAffected Versions
Version 0.7.5 rc2

Timeline

No history available yet.