CVE-2024-11172

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
20/03/2025
Last modified:
15/10/2025

Description

A vulnerability in danny-avila/librechat version git a1647d7 allows an unauthenticated attacker to cause a denial of service by sending a crafted payload to the server. The middleware `checkBan` is not surrounded by a try-catch block, and an unhandled exception will cause the server to crash. This issue is fixed in version 0.7.6.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:librechat:librechat:*:*:*:*:*:*:*:* 0.7.6 (excluding)