Security Advisory

CVE-2024-11172

CVE vulnerability detail — eXtreme Datacenter Security Operations

Published 2025-03-20 10:10:06
Last updated 2025-10-15 12:49:28
Assigner @huntr_ai
State PUBLISHED

Description

A vulnerability in danny-avila/librechat version git a1647d7 allows an unauthenticated attacker to cause a denial of service by sending a crafted payload to the server. The middleware `checkBan` is not surrounded by a try-catch block, and an unhandled exception will cause the server to crash. This issue is fixed in version 0.7.6.