BadHost Vulnerability Exposes Millions Of AI Agents
A critical vulnerability, CVE-2026-32625, has been identified in LibreChat, allowing for the exfiltration of server secrets via MCP Server URL Injection. The vulnerability was published on June 2, 2026.
Topics
Developing
- 883d Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore.
- 883d Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur.
- 883d Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est.
- 883d Sed ut perspiciatis unde omnis iste natus error sit voluptatem accusantium doloremque laudantium.
Sources · 7 independent
Bluesky Social
“CVE-2026-32625 - LibreChat Exfiltrates Server Secrets via MCP Server URL Injection CVE ID : CVE-2026-32625 Published : June 2, 2026, 11:16 p.m.”
Unlock the full story
Get a Pro subscription or above to see the live story progression and the full list of independent sources confirming each event as they happen.
Log in to upgrade