CVEs affecting projects tracked on Release Alert, from NVD & OSV.
CVE-2025-41258 — HIGH severity vulnerability | Release Alert
CVE-2025-41258
8
HIGHCVSS v3
Published
March 18, 2026
Affected
1 project
Assigned by
1e3a9e0f-5156-4bf8-b8a3-cc311bfc0f4a
Severity scale
010
Description
LibreChat version 0.8.1-rc2 uses the same JWT secret for the user session mechanism and RAG API which compromises the service-level authentication of the RAG API.