CVE-2025-59417
- EPSS 0.4%
- Veröffentlicht 18.09.2025 14:38:55
- Zuletzt bearbeitet 25.09.2025 15:32:15
Lobe Chat is an open-source artificial intelligence chat framework. Prior to version 1.129.4, there is a a cross-site scripting (XSS) vulnerability when handling chat message in lobe-chat that can be escalated to remote code execution on the user’s m...
CVE-2024-32965
- EPSS 23.9%
- Veröffentlicht 26.11.2024 19:15:23
- Zuletzt bearbeitet 23.09.2025 14:16:58
Lobe Chat is an open-source, AI chat framework. Versions of lobe-chat prior to 1.19.13 have an unauthorized ssrf vulnerability. An attacker can construct malicious requests to cause SSRF without logging in, attack intranet services, and leak sensitiv...
CVE-2024-47066
- EPSS 11.77%
- Veröffentlicht 23.09.2024 16:15:06
- Zuletzt bearbeitet 30.09.2024 18:03:58
Lobe Chat is an open-source artificial intelligence chat framework. Prior to version 1.19.13, server-side request forgery protection implemented in `src/app/api/proxy/route.ts` does not consider redirect and could be bypassed when attacker provides a...
CVE-2024-37895
- EPSS 0.55%
- Veröffentlicht 17.06.2024 20:15:13
- Zuletzt bearbeitet 08.10.2025 16:08:51
Lobe Chat is an open-source LLMs/AI chat framework. In affected versions if an attacker can successfully authenticate through SSO/Access Code, they can obtain the real backend API Key by modifying the base URL to their own attack URL on the frontend ...
- EPSS 52.96%
- Veröffentlicht 14.05.2024 15:37:18
- Zuletzt bearbeitet 30.09.2025 14:35:10
Lobe Chat is a chatbot framework that supports speech synthesis, multimodal, and extensible Function Call plugin system. Prior to 0.150.6, lobe-chat had an unauthorized Server-Side Request Forgery vulnerability in the /api/proxy endpoint. An attacker...
CVE-2024-24566
- EPSS 0.48%
- Veröffentlicht 31.01.2024 17:15:39
- Zuletzt bearbeitet 21.11.2024 08:59:26
Lobe Chat is a chatbot framework that supports speech synthesis, multimodal, and extensible Function Call plugin system. When the application is password-protected (deployed with the `ACCESS_CODE` option), it is possible to access plugins without pro...