Lobehub

Lobe Chat

16 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.17%
  • Veröffentlicht 10.08.2026 10:41:57
  • Zuletzt bearbeitet 10.08.2026 14:17:31

A stored cross-site scripting (XSS) vulnerability in lobehub/lobe-chat through v2.2.13 allows a low-privileged authenticated user to inject arbitrary JavaScript into the application by uploading a crafted SVG file as a user avatar.

Exploit
  • EPSS 0.18%
  • Veröffentlicht 02.07.2026 19:43:16
  • Zuletzt bearbeitet 14.07.2026 23:17:33

LobeChat through 2.2.9 contains a broken object level authorization vulnerability that allows authenticated attackers to access and modify other users' chat-group agent data by supplying arbitrary group identifiers. Attackers can invoke the getGroupA...

Exploit
  • EPSS 0.24%
  • Veröffentlicht 02.07.2026 19:42:27
  • Zuletzt bearbeitet 14.07.2026 23:17:33

LobeChat through 2.2.9 contains a broken access control vulnerability in the retrieval-augmented-generation semantic search functionality that allows authenticated attackers to access other users' data by exploiting missing user-identifier predicates...

Exploit
  • EPSS 0.24%
  • Veröffentlicht 02.07.2026 19:41:16
  • Zuletzt bearbeitet 14.07.2026 23:17:33

LobeChat before 2.2.10-canary.18 contains a server-side request forgery vulnerability that allows authenticated attackers to direct internal HTTP requests to arbitrary URLs by supplying user-controlled input to the skill import service (importFromUrl...

  • EPSS 0.15%
  • Veröffentlicht 02.07.2026 19:39:19
  • Zuletzt bearbeitet 14.07.2026 23:17:32

LobeChat through 2.2.9 server-database deployments are vulnerable to broken object-level authorization in MessageModel. The updateMessagePlugin, updatePluginState, updatePluginError, updateTTS and updateTranslate methods filter target rows by message...

  • EPSS 0.33%
  • Veröffentlicht 30.01.2026 20:16:41
  • Zuletzt bearbeitet 15.04.2026 00:35:42

LobeHub is an open source human-and-AI-agent network. Prior to version 1.143.3, the file upload feature in `Knowledge Base > File Upload` does not validate the integrity of the upload request, allowing users to intercept and modify the request parame...

  • EPSS 0.2%
  • Veröffentlicht 19.01.2026 16:53:32
  • Zuletzt bearbeitet 15.04.2026 00:35:42

LobeChat is an open source chat application platform. Prior to version 2.0.0-next.193, `knowledgeBase.removeFilesFromKnowledgeBase` tRPC ep allows authenticated users to delete files from any knowledge base without verifying ownership. `userId` filte...

  • EPSS 0.13%
  • Veröffentlicht 18.01.2026 23:15:48
  • Zuletzt bearbeitet 15.04.2026 00:35:42

LobeChat is an open source chat application platform. Prior to version 2.0.0-next.180, a stored Cross-Site Scripting (XSS) vulnerability in the Mermaid artifact renderer allows attackers to execute arbitrary JavaScript within the application context....

  • EPSS 0.3%
  • Veröffentlicht 17.10.2025 18:18:53
  • Zuletzt bearbeitet 15.04.2026 00:35:42

LobeChat is an open source chat application platform. The web-crawler package in LobeChat version 1.136.1 allows server-side request forgery (SSRF) in the tools.search.crawlPages tRPC endpoint. A client can supply an arbitrary urls array together wit...

Exploit
  • EPSS 0.3%
  • Veröffentlicht 25.09.2025 14:15:45
  • Zuletzt bearbeitet 08.10.2025 16:11:34

Lobe Chat is an open-source artificial intelligence chat framework. Prior to version 1.130.1, the project's OIDC redirect handling logic constructs the host and protocol of the final redirect URL based on the X-Forwarded-Host or Host headers and the ...