ghcr.io/danny-avila/librechat:v0.7.8 container image
GitHub Container RegistryScanned 14 Sept 2026
Deployed by 1 of 17,781 indexed charts (latest versions) at this tag.GitHub Container Registry all tags of ghcr.io/danny-avila/librechat
ghcr.io/danny-avila/librechat:v0.7.8 resolved to 7fe76551a78e, scanned 14 Sept 2026: 258 findings, 1 critical; deployed by 1 chart, among them librechat.
Radar Score
Radar Score is the sum of every finding’s contribution; the colour is the worst finding’s band.
Low findings
209 distinct on this digest
Low: findings whose contribution to the Radar Score is 1–14. Show every band
Findings for digest 7fe76551a78e as scanned on 14 Sept 2026 with syft 1.42.1 for linux/amd64, advisories as of 14 Sept 2026. Other architectures may differ.
| Severity | Advisory | Package | Fixed in |
|---|---|---|---|
| Low | GHSA-fx83-v9x8-x52w | protobufjs | 7.5.6 |
| Low | ALPINE-CVE-2026-2297 | python3 | 3.12.14-r0 |
| Low | GHSA-jggg-4jg4-v7c6 | protobufjs | 7.5.8 |
| Low | GHSA-4mjr-xmp4-gh2g | qs | 6.16.0 |
| Low | ALPINE-CVE-2026-56412 | expat | 2.8.2-r0 |
| Low | GHSA-48c2-rrv3-qjmp | yaml | 2.8.3 |
| Low | ALPINE-CVE-2026-50219 | expat | 2.8.2-r0 |
| Low | ALPINE-CVE-2026-56409 | expat | 2.8.2-r0 |
| Low | ALPINE-CVE-2026-27171 | zlib | 1.3.2-r0 |
| Low | ALPINE-CVE-2025-29088 | sqlite | 3.48.0-r4 |
| Low | ALPINE-CVE-2026-32777 | expat | 2.7.5-r0 |
| Low | GHSA-xx6v-rp6x-q39c | axios | 1.15.1 |
| Low | GHSA-f88m-g3jw-g9cj | sharp | 0.35.0 |
| Low | GHSA-898c-q2cr-xwhg | axios | 1.16.0 |
| Low | GHSA-r7g4-qg5f-qqm2 | nodemailer | 8.0.8 |
| Low | ALPINE-CVE-2026-56132 | expat | 2.8.2-r0 |
| Low | GHSA-rr7j-v2q5-chgv | langsmith | 0.5.19 |
| Low | GHSA-wrjc-x8rr-h8h6 | react-router | 7.18.0 |
| Low | GHSA-268h-hp4c-crq3 | nodemailer | 8.0.9 |
| Low | GHSA-wqvq-jvpq-h66f | nodemailer | 8.0.9 |
| Low | GHSA-2qvq-rjwj-gvw9 | handlebars | 4.7.9 |
| Low | ALPINE-CVE-2026-32778 | expat | 2.7.5-r0 |
| Low | GHSA-wmmp-3585-3rmp | nodemailer | 9.1.0 |
| Low | ALPINE-CVE-2026-32776 | expat | 2.7.5-r0 |
| Low | GHSA-gf3v-fwqg-4vh7 | @langchain/ | 1.1.14 |
| Low | ALPINE-CVE-2026-6042 | musl | 1.2.5-r10 |
| Low | GHSA-w9m9-85wc-3x92 | postcss-selector-parser | 6.1.3 |
| Low | GHSA-w7fw-mjwx-w883 | qs | 6.14.2 |
| Low | ALPINE-CVE-2026-22795 | openssl | 3.3.6-r0 |
| Low | GHSA-6rw7-vpxm-498p | qs | 6.14.1 |
| Low | GHSA-gcr2-9v8m-gq45 | @dicebear/ | 9.4.3 |
| Low | GHSA-gcr2-9v8m-gq45 | @dicebear/ | 9.4.3 |
| Low | ALPINE-CVE-2026-56131 | expat | 2.8.2-r0 |
| Low | ALPINE-CVE-2026-0864 | python3 | 3.12.14-r0 |
| Low | GHSA-v422-hmwv-36x6 | body-parser | 1.20.6 |
| Low | GHSA-jp4c-xjxw-mgf9 | pip | 26.1 |
| Low | GHSA-8m3c-c648-2xjj | nodemailer | 9.1.1 |
| Low | GHSA-mr9r-mww3-v6gv | @dicebear/ | 9.4.1 |
| Low | GHSA-mr9r-mww3-v6gv | @dicebear/ | 9.4.1 |
| Low | GHSA-v6h2-p8h4-qcjw | brace-expansion | 2.0.2 |
| Low | ALPINE-CVE-2025-68160 | openssl | 3.3.6-r0 |
| Low | GHSA-mphv-75cg-56wg | @langchain/ | 1.1.18 |
| Low | GHSA-58qw-9mgm-455v | pip | 26.1 |
| Low | GHSA-c7w3-x93f-qmm8 | nodemailer | 8.0.4 |
| Low | ALPINE-CVE-2026-4519 | python3 | 3.12.14-r0 |
| Low | GHSA-7rx3-28cr-v5wh | handlebars | 4.7.9 |
| Low | GHSA-xhjh-pmcv-23jw | axios | 1.15.1 |
| Low | ALPINE-CVE-2026-41080 | expat | 2.8.1-r0 |
| Low | GHSA-qvfw-j98x-7q72 | multer | 2.3.0 |
| Low | ALPINE-CVE-2025-69418 | openssl | 3.3.6-r0 |