CVE-2024-10361

Source
https://cve.org/CVERecord?id=CVE-2024-10361
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2024-10361.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2024-10361
Published
2025-03-20T10:09:09.995Z
Modified
2026-08-12T03:51:14.244501437Z
Severity
  • 8.1 (High) CVSS_V3 - CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H CVSS Calculator
Summary
Arbitrary File Deletion via Path Traversal in danny-avila/librechat
Details

An arbitrary file deletion vulnerability exists in danny-avila/librechat version v0.7.5-rc2, specifically within the /api/files endpoint. This vulnerability arises from improper input validation, allowing path traversal techniques to delete arbitrary files on the server. Attackers can exploit this to bypass security mechanisms and delete files outside the intended directory, including critical system files, user data, or application resources. This vulnerability impacts the integrity and availability of the system.

Database specific
{
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2024/10xxx/CVE-2024-10361.json",
    "cwe_ids": [
        "CWE-22"
    ],
    "cna_assigner": "@huntr_ai"
}
References

Affected packages

Git / github.com/danny-avila/librechat

Affected ranges

Type
GIT
Repo
https://github.com/danny-avila/librechat
Events
Database specific
Show details
{
    "cpe": "cpe:2.3:a:librechat:librechat:0.7.5:rc2:*:*:*:*:*:*",
    "source": [
        "CPE_STRING",
        "REFERENCES"
    ],
    "extracted_events": [
        {
            "introduced": "0.7.5-rc2"
        },
        {
            "last_affected": "0.7.5-rc2"
        }
    ]
}

Affected versions

0.*
0.7.5-rc2

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2024-10361.json"