Sunday, 13 September 2026
8 agent hacks today 7 vs yesterday (1)

LibreChat MCP integration flaws leak server secrets and allow cross-agent file deletion

Three vulnerabilities in LibreChat versions up to and including 0.8.3 (CVE-2026-32625, CVE-2026-44653, CVE-2026-44654) let authenticated users exfiltrate server environment secrets such as CREDS_KEY, JWT_SECRET and MONGO_URI via malicious MCP server URLs, read decrypted admin-managed MCP credentials with only VIEW access, and delete an owner's files globally from a shared agent. The issues are patched in versions 0.8.4-rc1 and 0.8.4.

Disclosed 2 June 2026 · Record updated 13 September 2026

Impact

Any authenticated user could obtain the installation's cryptographic keys and database credentials, and MCP server viewers could retrieve plaintext provider API keys and OAuth client secrets; shared-agent editors could destroy files used by the owner's other private agents.

Our coverage

No articles linked to this incident yet.

Sources

  1. nvd.nist.govhttps://nvd.nist.gov/vuln/detail/CVE-2026-32625
  2. nvd.nist.govhttps://nvd.nist.gov/vuln/detail/CVE-2026-44653
  3. nvd.nist.govhttps://nvd.nist.gov/vuln/detail/CVE-2026-44654