CVE-2025-8850
HIGH EPSS 33.6%
Published Oct 30, 20258mo ago · Modified Jun 17, 20262w ago
8.8 CVSS 3.1
Published Oct 30, 2025 8mo ago
Last Modified Jun 17, 2026 2w ago
Description
In danny-avila/librechat version 0.7.9, there is an insecure API design issue in the 2-Factor Authentication (2FA) flow. The system allows users to disable 2FA without requiring a valid OTP or backup code, bypassing the intended verification process. This vulnerability occurs because the backend does not properly validate the OTP or backup code when the API endpoint '/api/auth/2fa/disable' is directly accessed. This flaw can be exploited by authenticated users to weaken the security of their own accounts, although it does not lead to full account compromise.
CVSS Details
Base Score
Exploitability
Impact
Vector string
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Attack Vector Network
Attack Complexity Low
Privileges Required Low
User Interaction None
Scope Unchanged
Confidentiality High
Integrity High
Availability High
Threat Intelligence
EPSS Exploit Probability
33.6% percentile
Exploit & Patch Status
Public Exploit Known
Patch Available
Weaknesses 1
CWE-440
Affected Products 1
| Vendor | Product | Version | Range |
|---|---|---|---|
| librechat | librechat | 0.7.9 | any |
References 2
- github.com https://github.com/danny-avila/librechat/commit/7e4c8a5d0d2dbe5bf8fd272ff6acafb27d24744f
- huntr.com https://huntr.com/bounties/8e615709-f4de-41e2-b194-f0d91ed7c75e
Remediation
- github.com https://github.com/danny-avila/librechat/commit/7e4c8a5d0d2dbe5bf8fd272ff6acafb27d24744f
- huntr.com https://huntr.com/bounties/8e615709-f4de-41e2-b194-f0d91ed7c75e