LibreChat: agent file-upload authorization bypass and MCP OAuth token theft flaws
Two vulnerabilities were disclosed in LibreChat: CVE-2026-54027, where the POST /api/files/images endpoint let any authenticated user upload files into any agent's tool_resources without ownership or EDIT permission checks, and CVE-2026-54030, where the MCP OAuth implementation failed to validate the RFC 9728 resource parameter against the configured MCP server URL, allowing a malicious MCP server to steal access tokens. Both are fixed in versions 0.8.4-rc1 and 0.8.5 respectively.
Disclosed 25 June 2026 · Record updated 13 September 2026
Impact
Authenticated users could inject files into other users' agent tool resources (including context and execute_code), and a malicious MCP server could capture OAuth access tokens intended for a legitimate server.
Our coverage
No articles linked to this incident yet.
Sources
- nvd.nist.govhttps://nvd.nist.gov/vuln/detail/CVE-2026-54027
- nvd.nist.govhttps://nvd.nist.gov/vuln/detail/CVE-2026-54030
