CVE-2026-72594
- EPSS 0.17%
- Veröffentlicht 10.08.2026 10:41:57
- Zuletzt bearbeitet 10.08.2026 14:17:31
A stored cross-site scripting (XSS) vulnerability in lobehub/lobe-chat through v2.2.13 allows a low-privileged authenticated user to inject arbitrary JavaScript into the application by uploading a crafted SVG file as a user avatar.
- EPSS 0.18%
- Veröffentlicht 02.07.2026 19:43:16
- Zuletzt bearbeitet 14.07.2026 23:17:33
LobeChat through 2.2.9 contains a broken object level authorization vulnerability that allows authenticated attackers to access and modify other users' chat-group agent data by supplying arbitrary group identifiers. Attackers can invoke the getGroupA...
CVE-2026-59098
- EPSS 0.24%
- Veröffentlicht 02.07.2026 19:42:27
- Zuletzt bearbeitet 14.07.2026 23:17:33
LobeChat through 2.2.9 contains a broken access control vulnerability in the retrieval-augmented-generation semantic search functionality that allows authenticated attackers to access other users' data by exploiting missing user-identifier predicates...
CVE-2026-59095
- EPSS 0.24%
- Veröffentlicht 02.07.2026 19:41:16
- Zuletzt bearbeitet 14.07.2026 23:17:33
LobeChat before 2.2.10-canary.18 contains a server-side request forgery vulnerability that allows authenticated attackers to direct internal HTTP requests to arbitrary URLs by supplying user-controlled input to the skill import service (importFromUrl...
- EPSS 0.15%
- Veröffentlicht 02.07.2026 19:39:19
- Zuletzt bearbeitet 14.07.2026 23:17:32
LobeChat through 2.2.9 server-database deployments are vulnerable to broken object-level authorization in MessageModel. The updateMessagePlugin, updatePluginState, updatePluginError, updateTTS and updateTranslate methods filter target rows by message...
CVE-2026-23835
- EPSS 0.33%
- Veröffentlicht 30.01.2026 20:16:41
- Zuletzt bearbeitet 15.04.2026 00:35:42
LobeHub is an open source human-and-AI-agent network. Prior to version 1.143.3, the file upload feature in `Knowledge Base > File Upload` does not validate the integrity of the upload request, allowing users to intercept and modify the request parame...
CVE-2026-23522
- EPSS 0.2%
- Veröffentlicht 19.01.2026 16:53:32
- Zuletzt bearbeitet 15.04.2026 00:35:42
LobeChat is an open source chat application platform. Prior to version 2.0.0-next.193, `knowledgeBase.removeFilesFromKnowledgeBase` tRPC ep allows authenticated users to delete files from any knowledge base without verifying ownership. `userId` filte...
CVE-2026-23733
- EPSS 0.13%
- Veröffentlicht 18.01.2026 23:15:48
- Zuletzt bearbeitet 15.04.2026 00:35:42
LobeChat is an open source chat application platform. Prior to version 2.0.0-next.180, a stored Cross-Site Scripting (XSS) vulnerability in the Mermaid artifact renderer allows attackers to execute arbitrary JavaScript within the application context....
- EPSS 0.3%
- Veröffentlicht 17.10.2025 18:18:53
- Zuletzt bearbeitet 15.04.2026 00:35:42
LobeChat is an open source chat application platform. The web-crawler package in LobeChat version 1.136.1 allows server-side request forgery (SSRF) in the tools.search.crawlPages tRPC endpoint. A client can supply an arbitrary urls array together wit...
CVE-2025-59426
- EPSS 0.3%
- Veröffentlicht 25.09.2025 14:15:45
- Zuletzt bearbeitet 08.10.2025 16:11:34
Lobe Chat is an open-source artificial intelligence chat framework. Prior to version 1.130.1, the project's OIDC redirect handling logic constructs the host and protocol of the final redirect URL based on the X-Forwarded-Host or Host headers and the ...