ghcr.io/danny-avila/librechat:v0.7.7 container image
GitHub Container RegistryScanned 14 Sept 2026
Deployed by 1 of 17,781 indexed charts (latest versions) at this tag.GitHub Container Registry all tags of ghcr.io/danny-avila/librechat
ghcr.io/danny-avila/librechat:v0.7.7 resolved to 8c68abbe1cff, scanned 14 Sept 2026: 226 findings, 0 critical; deployed by 1 chart, among them librechat.
Radar Score
Radar Score is the sum of every finding’s contribution; the colour is the worst finding’s band.
Vulnerabilities
226 distinct on this digest
Findings for digest 8c68abbe1cff as scanned on 14 Sept 2026 with syft 1.42.1 for linux/amd64, advisories as of 14 Sept 2026. Other architectures may differ.
| Severity | Advisory | Package | Fixed in |
|---|---|---|---|
| High | ALPINE-CVE-2025-15467 | openssl | 3.3.6-r0 |
| High | GHSA-r5fr-rjxr-66jc | lodash | 4.18.0 |
| Medium | GHSA-2w6w-674q-4c4q | handlebars | 4.7.9 |
| Medium | GHSA-fjxv-7rqg-78g4 | form-data | 4.0.4 |
| Medium | GHSA-jc85-fpwf-qm7x | expr-eval | no fix listed |
| Medium | GHSA-5j98-mcp5-4vw2 | glob | 10.5.0 |
| Medium | GHSA-43fc-jf86-j433 | axios | 1.13.5 |
| Medium | GHSA-pq67-2wwv-3xjx | tar-fs | 3.0.7 |
| Medium | GHSA-xq3m-2v4x-88gg | protobufjs | 7.5.5 |
| Medium | GHSA-35jp-ww65-95wh | axios | 1.16.0 |
| Medium | ALPINE-CVE-2025-9230 | openssl | 3.3.5-r0 |
| Medium | ALPINE-CVE-2025-9231 | openssl | 3.3.5-r0 |
| Medium | GHSA-r399-636x-v7f6 | langchain | 0.3.37 |
| Medium | GHSA-r399-636x-v7f6 | @langchain/ | 0.3.80 |
| Medium | GHSA-jr5f-v2jv-69x6 | axios | 1.8.2 |
| Medium | GHSA-95m3-7q98-8xr5 | sha.js | 2.4.12 |
| Medium | GHSA-4hjh-wcwx-xvwj | axios | 1.12.0 |
| Medium | GHSA-5528-5vmv-3xc2 | multer | 2.1.1 |
| Medium | GHSA-2w69-qvjg-hvjx | @remix-run/ | 1.23.2 |
| Medium | GHSA-f23m-r3pf-42rh | lodash | 4.18.0 |
| Medium | GHSA-xxjr-mmjv-4gpg | lodash | 4.17.23 |
| Medium | GHSA-v52c-386h-88mc | multer | 2.1.0 |
| Medium | GHSA-xf7r-hgr6-v32p | multer | 2.1.0 |
| Medium | ALPINE-CVE-2026-31790 | openssl | 3.3.7-r0 |
| Medium | ALPINE-CVE-2025-9232 | openssl | 3.3.5-r0 |
| Medium | GHSA-37ch-88jc-xwx2 | path-to-regexp | 0.1.13 |
| Medium | GHSA-qjx8-664m-686j | js-cookie | 3.0.7 |
| Medium | GHSA-cpq7-6gpm-g9rc | cipher-base | 1.0.5 |
| Medium | GHSA-8cj5-5rvv-wf4v | tar-fs | 3.0.9 |
| Medium | GHSA-3mfm-83xf-c92r | handlebars | 4.7.9 |
| Medium | GHSA-xhpv-hc6g-r9c6 | handlebars | 4.7.9 |
| Medium | ALPINE-CVE-2026-28388 | openssl | 3.3.7-r0 |
| Medium | GHSA-99f4-grh7-6pcq | @grpc/ | 1.9.16 |
| Medium | GHSA-m7jm-9gc2-mpf2 | fast-xml-parser | 4.5.4 |
| Medium | ALPINE-CVE-2025-69421 | openssl | 3.3.6-r0 |
| Medium | GHSA-3xgq-45jj-v275 | cross-spawn | 7.0.5 |
| Medium | GHSA-p92q-9vqr-4j8v | axios | 1.16.0 |
| Medium | GHSA-vj76-c3g6-qr5v | tar-fs | 3.1.1 |
| Medium | ALPINE-CVE-2026-28387 | openssl | 3.3.7-r0 |
| Medium | GHSA-jmr7-xgp7-cmfj | fast-xml-parser | 4.5.4 |
| Medium | GHSA-96hv-2xvq-fx4p | ws | 8.21.0 |
| Medium | GHSA-3ppc-4f35-3m26 | minimatch | 9.0.6 |
| Medium | ALPINE-CVE-2026-28389 | openssl | 3.3.7-r0 |
| Medium | ALPINE-CVE-2026-28390 | openssl | 3.3.7-r0 |
| Medium | GHSA-pf86-5x62-jrwf | axios | 1.15.1 |
| Medium | GHSA-4pg4-qvpc-4q3h | multer | 2.0.0 |
| Low | ALPINE-CVE-2025-69420 | openssl | 3.3.6-r0 |
| Low | GHSA-j3q9-mxjg-w52f | path-to-regexp | 8.4.0 |
| Low | ALPINE-CVE-2025-31498 | c-ares | 1.34.5-r0 |
| Low | GHSA-44fp-w29j-9vj5 | multer | 2.0.0 |