ghcr.io/danny-avila/librechat:v0.7.8 container image
GitHub Container RegistryScanned 14 Sept 2026
Deployed by 1 of 17,781 indexed charts (latest versions) at this tag.GitHub Container Registry all tags of ghcr.io/danny-avila/librechat
ghcr.io/danny-avila/librechat:v0.7.8 resolved to 7fe76551a78e, scanned 14 Sept 2026: 258 findings, 1 critical; deployed by 1 chart, among them librechat.
Radar Score
Radar Score is the sum of every finding’s contribution; the colour is the worst finding’s band.
Medium findings
46 distinct on this digest
Medium: findings whose contribution to the Radar Score is 15–39. Show every band
Findings for digest 7fe76551a78e as scanned on 14 Sept 2026 with syft 1.42.1 for linux/amd64, advisories as of 14 Sept 2026. Other architectures may differ.
| Severity | Advisory | Package | Fixed in |
|---|---|---|---|
| Medium | GHSA-2w6w-674q-4c4q | handlebars | 4.7.9 |
| Medium | GHSA-fjxv-7rqg-78g4 | form-data | 4.0.4 |
| Medium | GHSA-jc85-fpwf-qm7x | expr-eval | no fix listed |
| Medium | GHSA-5j98-mcp5-4vw2 | glob | 10.5.0 |
| Medium | ALPINE-CVE-2025-4517 | python3 | 3.12.11-r0 |
| Medium | GHSA-43fc-jf86-j433 | axios | 1.13.5 |
| Medium | PYSEC-2025-49 | setuptools | 78.1.1 |
| Medium | GHSA-xq3m-2v4x-88gg | protobufjs | 7.5.5 |
| Medium | GHSA-35jp-ww65-95wh | axios | 1.16.0 |
| Medium | ALPINE-CVE-2025-9230 | openssl | 3.3.5-r0 |
| Medium | ALPINE-CVE-2025-9231 | openssl | 3.3.5-r0 |
| Medium | ALPINE-CVE-2025-4138 | python3 | 3.12.11-r0 |
| Medium | ALPINE-CVE-2025-59375 | expat | 2.7.2-r0 |
| Medium | GHSA-r399-636x-v7f6 | langchain | 0.3.37 |
| Medium | GHSA-r399-636x-v7f6 | @langchain/ | 0.3.80 |
| Medium | GHSA-4hjh-wcwx-xvwj | axios | 1.12.0 |
| Medium | GHSA-5528-5vmv-3xc2 | multer | 2.1.1 |
| Medium | GHSA-2w69-qvjg-hvjx | @remix-run/ | 1.23.2 |
| Medium | GHSA-f23m-r3pf-42rh | lodash | 4.18.0 |
| Medium | GHSA-xxjr-mmjv-4gpg | lodash | 4.17.23 |
| Medium | GHSA-v52c-386h-88mc | multer | 2.1.0 |
| Medium | GHSA-xf7r-hgr6-v32p | multer | 2.1.0 |
| Medium | ALPINE-CVE-2026-6100 | python3 | 3.12.14-r0 |
| Medium | ALPINE-CVE-2026-31790 | openssl | 3.3.7-r0 |
| Medium | ALPINE-CVE-2025-9232 | openssl | 3.3.5-r0 |
| Medium | ALPINE-CVE-2025-4330 | python3 | 3.12.11-r0 |
| Medium | GHSA-37ch-88jc-xwx2 | path-to-regexp | 0.1.13 |
| Medium | GHSA-qjx8-664m-686j | js-cookie | 3.0.7 |
| Medium | ALPINE-CVE-2026-66046 | expat | 2.8.4-r0 |
| Medium | GHSA-3mfm-83xf-c92r | handlebars | 4.7.9 |
| Medium | GHSA-xhpv-hc6g-r9c6 | handlebars | 4.7.9 |
| Medium | ALPINE-CVE-2026-28388 | openssl | 3.3.7-r0 |
| Medium | GHSA-99f4-grh7-6pcq | @grpc/ | 1.9.16 |
| Medium | GHSA-m7jm-9gc2-mpf2 | fast-xml-parser | 5.3.5 |
| Medium | ALPINE-CVE-2025-69421 | openssl | 3.3.6-r0 |
| Medium | GHSA-3xgq-45jj-v275 | cross-spawn | 7.0.5 |
| Medium | GHSA-p92q-9vqr-4j8v | axios | 1.16.0 |
| Medium | ALPINE-CVE-2026-28387 | openssl | 3.3.7-r0 |
| Medium | ALPINE-CVE-2026-11940 | python3 | 3.12.14-r0 |
| Medium | GHSA-jmr7-xgp7-cmfj | fast-xml-parser | 5.3.6 |
| Medium | GHSA-96hv-2xvq-fx4p | ws | 8.21.0 |
| Medium | GHSA-3ppc-4f35-3m26 | minimatch | 9.0.6 |
| Medium | ALPINE-CVE-2026-28389 | openssl | 3.3.7-r0 |
| Medium | ALPINE-CVE-2026-28390 | openssl | 3.3.7-r0 |
| Medium | GHSA-pf86-5x62-jrwf | axios | 1.15.1 |
| Medium | GHSA-4pg4-qvpc-4q3h | multer | 2.0.0 |