CVE-2026-31943 | danny-avila LibreChat up to 0.8.2 HTTP Request domain.ts isPrivateIP server-side request forgery (GHSA-w5r7-4f94-vp4c)
A vulnerability identified as critical has been detected in danny-avila LibreChat up to 0.8.2. Affected by this vulnerability is the function isPrivateIP of the file packages/api/src/auth/domain.ts of the component HTTP Request Handler. This manipulation causes server-side request forgery.
This vulnerability appears as CVE-2026-31943. The attack may be initiated remotely. There is no available exploit.
You should upgrade the affected component.