CVE-2026-44654
LibreChat is an enhanced ChatGPT clone that supports multiple AI providers. In versions up to and including 0.8.3, a shared-agent editor can delete file records through DELETE /api/files that the owner has reused across multiple agents. The deletion removes the file globally, not just from the shared agent, breaking the owner's other private agents that reference the same file_id.
The private agent retains a stale file_id reference that no longer resolves. A shared-agent editor can destroy files that the owner uses across multiple agents. The owner's private agents, which the attacker has no access to, break silently with stale file_id references.
This is a cross-agent integrity violation: editing access to one agent should not affect another. Version 0.8.4 contains a patch.
- Public exploit or PoC is available
- SSVC automatable: yes - attacks can be scripted at scale
- CVSS base score ≥ 7.0
ATT&CK techniques
1Techniques this CVE enables - linked via CWECAPECATT&CK. High◆ = named directly in ATT&CK or Nuclei templates.
▤ Build a SIEM detection for these techniques