CVE-2026-23835
- EPSS 0.02%
- Veröffentlicht 30.01.2026 20:16:41
- Zuletzt bearbeitet 04.02.2026 16:34:21
LobeHub is an open source human-and-AI-agent network. Prior to version 1.143.3, the file upload feature in `Knowledge Base > File Upload` does not validate the integrity of the upload request, allowing users to intercept and modify the request parame...
CVE-2026-23522
- EPSS 0.05%
- Veröffentlicht 19.01.2026 16:53:32
- Zuletzt bearbeitet 26.01.2026 15:05:39
LobeChat is an open source chat application platform. Prior to version 2.0.0-next.193, `knowledgeBase.removeFilesFromKnowledgeBase` tRPC ep allows authenticated users to delete files from any knowledge base without verifying ownership. `userId` filte...
CVE-2026-23733
- EPSS 0.09%
- Veröffentlicht 18.01.2026 23:15:48
- Zuletzt bearbeitet 26.01.2026 15:05:39
LobeChat is an open source chat application platform. Prior to version 2.0.0-next.180, a stored Cross-Site Scripting (XSS) vulnerability in the Mermaid artifact renderer allows attackers to execute arbitrary JavaScript within the application context....
- EPSS 0.04%
- Veröffentlicht 17.10.2025 18:18:53
- Zuletzt bearbeitet 21.10.2025 19:31:50
LobeChat is an open source chat application platform. The web-crawler package in LobeChat version 1.136.1 allows server-side request forgery (SSRF) in the tools.search.crawlPages tRPC endpoint. A client can supply an arbitrary urls array together wit...
CVE-2025-59426
- EPSS 0.12%
- Veröffentlicht 25.09.2025 14:15:45
- Zuletzt bearbeitet 08.10.2025 16:11:34
Lobe Chat is an open-source artificial intelligence chat framework. Prior to version 1.130.1, the project's OIDC redirect handling logic constructs the host and protocol of the final redirect URL based on the X-Forwarded-Host or Host headers and the ...
CVE-2025-59417
- EPSS 0.09%
- Veröffentlicht 18.09.2025 14:38:55
- Zuletzt bearbeitet 25.09.2025 15:32:15
Lobe Chat is an open-source artificial intelligence chat framework. Prior to version 1.129.4, there is a a cross-site scripting (XSS) vulnerability when handling chat message in lobe-chat that can be escalated to remote code execution on the user’s m...
CVE-2024-32965
- EPSS 0.16%
- Veröffentlicht 26.11.2024 19:15:23
- Zuletzt bearbeitet 23.09.2025 14:16:58
Lobe Chat is an open-source, AI chat framework. Versions of lobe-chat prior to 1.19.13 have an unauthorized ssrf vulnerability. An attacker can construct malicious requests to cause SSRF without logging in, attack intranet services, and leak sensitiv...
CVE-2024-47066
- EPSS 5.58%
- Veröffentlicht 23.09.2024 16:15:06
- Zuletzt bearbeitet 30.09.2024 18:03:58
Lobe Chat is an open-source artificial intelligence chat framework. Prior to version 1.19.13, server-side request forgery protection implemented in `src/app/api/proxy/route.ts` does not consider redirect and could be bypassed when attacker provides a...
CVE-2024-37895
- EPSS 0.79%
- Veröffentlicht 17.06.2024 20:15:13
- Zuletzt bearbeitet 08.10.2025 16:08:51
Lobe Chat is an open-source LLMs/AI chat framework. In affected versions if an attacker can successfully authenticate through SSO/Access Code, they can obtain the real backend API Key by modifying the base URL to their own attack URL on the frontend ...
- EPSS 67.57%
- Veröffentlicht 14.05.2024 15:37:18
- Zuletzt bearbeitet 30.09.2025 14:35:10
Lobe Chat is a chatbot framework that supports speech synthesis, multimodal, and extensible Function Call plugin system. Prior to 0.150.6, lobe-chat had an unauthorized Server-Side Request Forgery vulnerability in the /api/proxy endpoint. An attacker...