Danny Avila
24 exploits
Active since Mar 2025
danny-avila/librechat <0.7.5-rc2 - Code Injection
CVSS 4.6
librechat v0.7.5-rc2 - Arbitrary File Deletion via Path Traversal in /api/files Endpoint
CVSS 9.1
LibreChat 0.7.5 - Missing Authorization for Prompt Sharing and Creation
CVSS 5.4
LibreChat 0.7.5-rc2 Attachments - Insecure Direct Object Reference
CVSS 6.5
librechat < 0.7.6 - Authenticated Prompt Deletion via GroupID Parameter
CVSS 5.3
danny-avila/librechat <3c94ff2 - DoS
CVSS 7.5
librechat < 0.7.6 - Path Traversal and Arbitrary File Write via Multer Middleware
CVSS 8.8
librechat < 0.7.6 - Unauthenticated Denial of Service via Unrestricted File Upload Size
CVSS 7.5
librechat < 0.7.6 - Unauthenticated Denial of Service via Unhandled Exception in checkBan Middleware
CVSS 7.5
librechat < 0.7.6 - Denial of Service via Malformed API Input
CVSS 6.5
danny-avila/librechat <0.7.6 - Code Injection
CVSS 5.3
LibreChat 0.0.6-0.7.7-rc1 - Unauthenticated Arbitrary Chat Data Exposure via Meilisearch Test Endpoint
CVSS 7.5
danny-avila/librechat <0.7.8 - Info Disclosure
CVSS 3.1
LibreChat < 0.8.1 - Stored Cross-Site Scripting via IconURL Parameter
CVSS 5.4
LibreChat < 0.8.1 - Improperly Controlled Modification of Dynamically-Determined Object Attributes via PATCH Endpoint
CVSS 6.5
LibreChat 0.8.1-rc2 - Authenticated Improper Access Control in File Upload and Search
CVSS 7.1
LibreChat 0.8.1-rc2 - Authenticated Improper Access Control via Agent Permissions Query
CVSS 4.3
LibreChat Actions - Internal Service Server-Side Request Forgery
CVSS 9.1
danny-avila/librechat - Mass Assignment
CVSS 7.5
danny-avila/librechat - Use After Free
CVSS 5.7
librechat < 0.7.9 - Improper Access Control in checkAccess Function
CVSS 5.3
LibreChat 0.7.9 - Denial of Service via Unbounded Parameters in /api/memories Endpoint
CVSS 7.5
danny-avila/librechat <0.7.9 - Auth Bypass
CVSS 8.8
LibreChat < 0.8.2-rc2 - Authenticated Remote Code Execution via MCP Stdio Transport
CVSS 9.1