Sploitus

CVE-2025-8850

No indexed exploits for CVE-2025-8850 yet

In danny-avila/librechat version 0.7.9, there is an insecure API design issue in the 2-Factor Authentication (2FA) flow. The system allows users to disable 2FA without requiring a valid OTP or backup code, bypassing the intended verification process. This vulnerability occurs because the backend does not properly validate the OTP or backup code when the API endpoint '/api/auth/2fa/disable' is directly accessed. This flaw can be exploited by authenticated users to weaken the security of their own accounts, although it does not lead to full account compromise.

Affected products
Librechat
Librechat
= 0.7.9
Fix
Available
CVSS 3.1
8.8 HIGH
EPSS
0.4% (34th percentile)
Weakness
CWE-440
NVD status
Analyzed
Published
2025-10-30
CVE-2025-8850 at NVD
Authoritative description, scoring and affected products

No indexed exploits for CVE-2025-8850 yet

Our index is partial: it proves presence, never absence

No exploit for CVE-2025-8850 has been indexed yet. Our index is built from live traffic and upstream syncs, so this page can only say what it knows — not that no exploit exists.