LibreChat MCP/agent flaws enable SSRF and OAuth token exfiltration
Two vulnerabilities in LibreChat's agent actions and Model Context Protocol support allow attackers to bypass SSRF protections to reach internal resources (CVE-2026-31945) and to exfiltrate victims' OAuth tokens via credential placeholder substitution in attacker-created MCP server headers (CVE-2026-31951). Patches are available in versions 0.8.3-rc1 and 0.8.3-rc2 respectively.
Disclosed 27 March 2026 · Record updated 13 September 2026
Impact
Attackers could access internal resources such as an internal RAG API or cloud instance metadata endpoints, and could steal OAuth access tokens from users who call tools on a malicious MCP server.
Our coverage
No articles linked to this incident yet.
Sources
- nvd.nist.govhttps://nvd.nist.gov/vuln/detail/CVE-2026-31945
- nvd.nist.govhttps://nvd.nist.gov/vuln/detail/CVE-2026-31951
