{"api_version":"v1","generated_at":"2026-10-09T09:00:00+00:00","product":{"cve_count":30,"evidence_gap_note":"This identity is present in BlackTree CVE records, but no product-specific publisher support or retirement history is currently registered in Lifecycle.","id":"security:cve-danny-avila-librechat-f0cd8a676e24","lifecycle_state":"evidence_gap","linked_lifecycle_url":null,"name":"LibreChat","next_cursor":null,"observations":[{"affected":"< 0.8.4-rc1","affected_versions_present":true,"cve_id":"CVE-2026-54024","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-54024","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-06-25T17:55:53.764Z","patch_url":"","primary_source":"","published":"2026-06-25T15:54:12.571Z"},{"affected":"< 0.8.4-rc1","affected_versions_present":true,"cve_id":"CVE-2026-54025","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-54025","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-06-25T18:02:29.089Z","patch_url":"https://github.com/danny-avila/LibreChat/security/advisories/GHSA-3phr-62qf-cxf3","primary_source":"","published":"2026-06-25T15:53:17.026Z"},{"affected":"< 0.8.4-rc1","affected_versions_present":true,"cve_id":"CVE-2026-54027","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-54027","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-06-26T15:20:51.701Z","patch_url":"","primary_source":"","published":"2026-06-25T15:52:02.234Z"},{"affected":"< 0.8.4-rc1","affected_versions_present":true,"cve_id":"CVE-2026-54029","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-54029","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-06-26T18:43:04.154Z","patch_url":"","primary_source":"","published":"2026-06-25T15:51:23.822Z"},{"affected":"< 0.8.4-rc1","affected_versions_present":true,"cve_id":"CVE-2026-54033","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-54033","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-06-25T17:43:57.186Z","patch_url":"https://github.com/danny-avila/LibreChat/security/advisories/GHSA-gc9r-88c3-7qhq","primary_source":"","published":"2026-06-25T15:50:41.754Z"},{"affected":"< 0.8.4-rc1","affected_versions_present":true,"cve_id":"CVE-2026-54037","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-54037","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-06-25T18:19:33.773Z","patch_url":"","primary_source":"","published":"2026-06-25T15:49:48.046Z"},{"affected":"< 0.8.5","affected_versions_present":true,"cve_id":"CVE-2026-54030","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-54030","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-06-26T02:04:54.939Z","patch_url":"","primary_source":"","published":"2026-06-25T15:48:00.480Z"},{"affected":"< 0.8.4-rc1","affected_versions_present":true,"cve_id":"CVE-2026-54040","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-54040","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-06-25T18:13:32.543Z","patch_url":"","primary_source":"","published":"2026-06-25T15:45:23.953Z"},{"affected":"< 0.8.4-rc1","affected_versions_present":true,"cve_id":"CVE-2026-54036","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-54036","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-06-25T16:01:59.612Z","patch_url":"","primary_source":"","published":"2026-06-25T15:39:33.850Z"},{"affected":"< 0.8.5","affected_versions_present":true,"cve_id":"CVE-2026-44654","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-44654","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-06-03T13:12:00.527Z","patch_url":"","primary_source":"","published":"2026-06-02T22:47:29.235Z"},{"affected":"< 0.8.4","affected_versions_present":true,"cve_id":"CVE-2026-44653","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-44653","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-06-03T19:00:27.312Z","patch_url":"https://github.com/danny-avila/LibreChat/security/advisories/GHSA-6vqg-rgpm-qvf9","primary_source":"","published":"2026-06-02T22:40:20.672Z"},{"affected":"< 0.8.4-rc1","affected_versions_present":true,"cve_id":"CVE-2026-32625","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-32625","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-06-03T14:07:46.872Z","patch_url":"https://github.com/danny-avila/LibreChat/security/advisories/GHSA-4pcc-j6m6-wcwx","primary_source":"","published":"2026-06-02T22:35:00.859Z"},{"affected":"< 0.8.3-rc1","affected_versions_present":true,"cve_id":"CVE-2026-31942","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-31942","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-06-03T13:12:43.716Z","patch_url":"https://github.com/danny-avila/LibreChat/security/advisories/GHSA-5jcj-rh68-cgj7","primary_source":"","published":"2026-06-02T22:22:13.527Z"},{"affected":"< 0.8.4","affected_versions_present":true,"cve_id":"CVE-2026-34371","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-34371","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-04-08T16:14:43.926Z","patch_url":"","primary_source":"","published":"2026-04-07T21:08:13.175Z"},{"affected":">= v0.8.2-rc1, <= v0.8.3-rc1","affected_versions_present":true,"cve_id":"CVE-2026-31951","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-31951","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-03-31T13:46:25.297Z","patch_url":"","primary_source":"","published":"2026-03-27T19:29:25.892Z"},{"affected":">= 0.8.2-rc2, < 0.8.2","affected_versions_present":true,"cve_id":"CVE-2026-31950","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-31950","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-03-27T19:55:24.141Z","patch_url":"","primary_source":"","published":"2026-03-27T19:25:25.007Z"},{"affected":">= 0.8.2-rc2, < 0.8.3-rc1","affected_versions_present":true,"cve_id":"CVE-2026-31945","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-31945","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-03-30T19:00:53.475Z","patch_url":"https://github.com/danny-avila/LibreChat/security/advisories/GHSA-f92m-jpv7-55p2","primary_source":"","published":"2026-03-27T19:23:53.395Z"},{"affected":"< 0.8.3","affected_versions_present":true,"cve_id":"CVE-2026-31943","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-31943","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-03-31T19:10:14.342Z","patch_url":"","primary_source":"","published":"2026-03-27T19:21:50.653Z"},{"affected":"0.8.1-rc2","affected_versions_present":true,"cve_id":"CVE-2025-41258","cve_url":"https://cve.blacktree.nl/cve/CVE-2025-41258","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-03-18T14:19:49.089Z","patch_url":"","primary_source":"","published":"2026-03-18T11:08:19.866Z"},{"affected":"< 0.8.3-rc1","affected_versions_present":true,"cve_id":"CVE-2026-31949","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-31949","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-03-16T13:43:45.488Z","patch_url":"https://github.com/danny-avila/LibreChat/security/advisories/GHSA-5m32-chq6-232p","primary_source":"","published":"2026-03-13T19:47:24.653Z"},{"affected":">= v0.8.2, <= 0.8.2-rc3","affected_versions_present":true,"cve_id":"CVE-2026-31944","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-31944","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-03-16T13:41:21.254Z","patch_url":"","primary_source":"","published":"2026-03-13T19:44:30.850Z"},{"affected":"< v0.8.2-rc2","affected_versions_present":true,"cve_id":"CVE-2026-22252","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-22252","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2026-01-12T18:48:33.821Z","patch_url":"https://github.com/danny-avila/LibreChat/commit/211b39f3113d4e6ecab84be0a83f4e9c9dea127f","primary_source":"","published":"2026-01-12T18:01:48.399Z"},{"affected":"LibreChat: >= 0.8.1-rc2, 0.8.2-rc2","affected_versions_present":true,"cve_id":"CVE-2025-69222","cve_url":"https://cve.blacktree.nl/cve/CVE-2025-69222","fixed":"0.8.1-rc2.","last_modified":"2026-01-07T21:34:00.607Z","patch_url":"https://github.com/danny-avila/LibreChat/commit/3b41e392ba5c0d603c1737d8582875e04eaa6e02","primary_source":"","published":"2026-01-07T21:17:17.590Z"},{"affected":"LibreChat: < 0.8.1-rc2","affected_versions_present":true,"cve_id":"CVE-2025-69221","cve_url":"https://cve.blacktree.nl/cve/CVE-2025-69221","fixed":"0.8.2-rc2.","last_modified":"2026-01-07T21:07:58.109Z","patch_url":"https://github.com/danny-avila/LibreChat/commit/06ba025bd95574c815ac6968454be7d3b024391c","primary_source":"","published":"2026-01-07T21:01:13.918Z"},{"affected":"LibreChat: >= 0.8.1-rc2, < 0.8.2-rc2","affected_versions_present":true,"cve_id":"CVE-2025-69220","cve_url":"https://cve.blacktree.nl/cve/CVE-2025-69220","fixed":"0.8.2-rc2.","last_modified":"2026-01-07T21:33:56.352Z","patch_url":"https://github.com/danny-avila/LibreChat/commit/4b9c6ab1cb9de626736de700c7981f38be08d237","primary_source":"","published":"2026-01-07T20:49:00.454Z"},{"affected":"LibreChat: <= 0.8.1","affected_versions_present":true,"cve_id":"CVE-2025-66452","cve_url":"https://cve.blacktree.nl/cve/CVE-2025-66452","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2025-12-12T19:28:19.177Z","patch_url":"","primary_source":"","published":"2025-12-11T22:52:20.442Z"},{"affected":"LibreChat: < 0.8.1","affected_versions_present":true,"cve_id":"CVE-2025-66451","cve_url":"https://cve.blacktree.nl/cve/CVE-2025-66451","fixed":"0.8.1.","last_modified":"2025-12-12T19:29:24.539Z","patch_url":"https://github.com/danny-avila/LibreChat/commit/01413eea3d3c1454d32ca9704fa9640407839737","primary_source":"","published":"2025-12-11T22:33:24.079Z"},{"affected":"LibreChat: < 0.8.1","affected_versions_present":true,"cve_id":"CVE-2025-66450","cve_url":"https://cve.blacktree.nl/cve/CVE-2025-66450","fixed":"0.8.1.","last_modified":"2025-12-12T19:30:38.502Z","patch_url":"https://github.com/danny-avila/LibreChat/commit/6fa94d3eb8f5779363226d10dccf8b01a735744c","primary_source":"","published":"2025-12-11T22:05:47.384Z"},{"affected":"LibreChat: < 0.8.1-rc2","affected_versions_present":true,"cve_id":"CVE-2025-66201","cve_url":"https://cve.blacktree.nl/cve/CVE-2025-66201","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2025-12-01T14:11:07.641Z","patch_url":"","primary_source":"","published":"2025-11-29T01:26:18.757Z"},{"affected":">= 0.0.6, < 0.7.7","affected_versions_present":true,"cve_id":"CVE-2025-54868","cve_url":"https://cve.blacktree.nl/cve/CVE-2025-54868","fixed":"0.7.7.","last_modified":"2025-08-05T16:19:02.005Z","patch_url":"https://github.com/danny-avila/LibreChat/commit/0e8041bcac616949c42a68dfb8f108ccc4db5151","primary_source":"","published":"2025-08-05T04:53:08.166Z"}],"source_generated_at":"2026-10-09T06:17:25.511Z","vendor":"danny-avila"}}
