An unhandled exception in the danny-avila/librechat repository, version git 600d217, can cause the server to crash, leading to a full denial of service. This issue occurs when certain API endpoints receive malformed input, resulting in an uncaught exception. Although a valid JWT is required to exploit this vulnerability, LibreChat allows open registration, enabling unauthenticated attackers to create an account and perform the attack. The issue is fixed in version 0.7.6.
                
            References
                    | Link | Resource | 
|---|---|
| https://github.com/danny-avila/librechat/commit/95a212534f1c5991bd1231a34ac3668b4b592cc3 | Patch | 
| https://huntr.com/bounties/4cebf926-c17f-4836-868b-e1de86221cec | Exploit Third Party Advisory | 
Configurations
                    History
                    15 Jul 2025, 16:03
| Type | Values Removed | Values Added | 
|---|---|---|
| Summary | 
 | |
| CPE | cpe:2.3:a:librechat:librechat:*:*:*:*:*:*:*:* | |
| First Time | Librechat Librechat librechat | |
| References | () https://github.com/danny-avila/librechat/commit/95a212534f1c5991bd1231a34ac3668b4b592cc3 - Patch | |
| References | () https://huntr.com/bounties/4cebf926-c17f-4836-868b-e1de86221cec - Exploit, Third Party Advisory | 
20 Mar 2025, 10:15
| Type | Values Removed | Values Added | 
|---|---|---|
| New CVE | 
Information
                Published : 2025-03-20 10:15
Updated : 2025-07-15 16:03
NVD link : CVE-2024-11173
Mitre link : CVE-2024-11173
CVE.ORG link : CVE-2024-11173
JSON object : View
Products Affected
                librechat
- librechat
CWE
                
                    
                        
                        CWE-248
                        
            Uncaught Exception
