A vulnerability in danny-avila/librechat version git 81f2936 allows for path traversal due to improper sanitization of file paths by the multer middleware. This can lead to arbitrary file write and potentially remote code execution. The issue is fixed in version 0.7.6.
CVE ID: CVE-2024-11170
CVSS Base Severity: HIGH
CVSS Base Score: 8.8
CVSS Vector: CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Vendor: danny-avila
Product: danny-avila/librechat
EPSS Score: 0.47% (probability of being exploited)
EPSS Percentile: 63.4% (scored less or equal to compared to others)
EPSS Date: 2025-04-18 (when was this score calculated)