{"id":"CVE-2026-31943","summary":"LibreChat has SSRF protection bypass via IPv4-mapped IPv6 normalization in isPrivateIP","details":"LibreChat is a ChatGPT clone with additional features. Prior to version 0.8.3, `isPrivateIP()` in `packages/api/src/auth/domain.ts` fails to detect IPv4-mapped IPv6 addresses in their hex-normalized form, allowing any authenticated user to bypass SSRF protection and make the server issue HTTP requests to internal network resources — including cloud metadata services (e.g., AWS `169.254.169.254`), loopback, and RFC1918 ranges. Version 0.8.3 fixes the issue.","aliases":["GHSA-w5r7-4f94-vp4c"],"modified":"2026-08-12T03:51:45.823099796Z","published":"2026-03-27T19:21:50.653Z","database_specific":{"cwe_ids":["CWE-918"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/31xxx/CVE-2026-31943.json","cna_assigner":"GitHub_M"},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/31xxx/CVE-2026-31943.json"},{"type":"ADVISORY","url":"https://github.com/danny-avila/LibreChat/security/advisories/GHSA-w5r7-4f94-vp4c"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-31943"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/danny-avila/librechat","events":[{"introduced":"0"},{"fixed":"cfbe812d63451c1578faa9a13b7e77e0c9a9789b"},{"introduced":"9eeec6bc4f5e856ac65f50784254d484b2808622"},{"last_affected":"7e85cf71bd271d552576b2ba23ec1fb72bdcaaa1"}],"database_specific":{"source":["CPE_RANGE","CPE_STRING"],"cpe":["cpe:2.3:a:librechat:librechat:*:*:*:*:*:*:*:*","cpe:2.3:a:librechat:librechat:0.8.3:rc1:*:*:*:*:*:*","cpe:2.3:a:librechat:librechat:0.8.3:rc2:*:*:*:*:*:*"],"extracted_events":[{"introduced":"0"},{"fixed":"0.8.3"},{"introduced":"0.8.3-rc1"},{"last_affected":"0.8.3-rc1"},{"introduced":"0.8.3-rc2"},{"last_affected":"0.8.3-rc2"}]}}],"versions":["0.8.3-rc1","0.8.3-rc2","v0.8.3-rc2","chart-1.9.9","v0.8.3-rc1","chart-1.9.8"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-31943.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:N"}]}