- EPSS 0.18%
- Veröffentlicht 02.07.2026 19:43:16
- Zuletzt bearbeitet 14.07.2026 23:17:33
LobeChat through 2.2.9 contains a broken object level authorization vulnerability that allows authenticated attackers to access and modify other users' chat-group agent data by supplying arbitrary group identifiers. Attackers can invoke the getGroupA...
CVE-2026-59098
- EPSS 0.24%
- Veröffentlicht 02.07.2026 19:42:27
- Zuletzt bearbeitet 14.07.2026 23:17:33
LobeChat through 2.2.9 contains a broken access control vulnerability in the retrieval-augmented-generation semantic search functionality that allows authenticated attackers to access other users' data by exploiting missing user-identifier predicates...
CVE-2026-59095
- EPSS 0.24%
- Veröffentlicht 02.07.2026 19:41:16
- Zuletzt bearbeitet 14.07.2026 23:17:33
LobeChat before 2.2.10-canary.18 contains a server-side request forgery vulnerability that allows authenticated attackers to direct internal HTTP requests to arbitrary URLs by supplying user-controlled input to the skill import service (importFromUrl...
- EPSS 0.15%
- Veröffentlicht 02.07.2026 19:39:19
- Zuletzt bearbeitet 14.07.2026 23:17:32
LobeChat through 2.2.9 server-database deployments are vulnerable to broken object-level authorization in MessageModel. The updateMessagePlugin, updatePluginState, updatePluginError, updateTTS and updateTranslate methods filter target rows by message...
CVE-2026-58578
- EPSS 0.31%
- Veröffentlicht 02.07.2026 19:38:21
- Zuletzt bearbeitet 14.07.2026 23:17:32
LobeChat before version 2.2.10-canary.15 contains a regular expression denial of service (ReDoS) vulnerability that allows authenticated attackers to block the Node.js event loop by supplying a catastrophic-backtracking pattern in a GitHub repository...
- EPSS 1.78%
- Veröffentlicht 23.06.2026 18:18:07
- Zuletzt bearbeitet 25.06.2026 20:18:11
LobeHub is a work-and-lifestyle space to find, build, and collaborate with agent teammates that grow with you. Prior to 2.1.57, the /webapi/proxy endpoint on app.lobehub.com accepts a URL in the POST body and fetches it server-side without any authen...
CVE-2026-42045
- EPSS 0.27%
- Veröffentlicht 12.05.2026 16:47:32
- Zuletzt bearbeitet 19.05.2026 18:19:44
LobeHub is a work-and-lifestyle space to find, build, and collaborate with agent teammates that grow with you. Prior to 2.1.48, when LobeChat processes custom tags in the Render process of src/features/Portal/Artifacts/Body/Renderer/index.tsx, if no ...
CVE-2026-39411
- EPSS 0.13%
- Veröffentlicht 08.04.2026 19:37:43
- Zuletzt bearbeitet 24.07.2026 21:10:00
LobeHub is a work-and-lifestyle space to find, build, and collaborate with agent teammates that grow with you. Prior to 2.1.48, the webapi authentication layer trusts a client-controlled X-lobe-chat-auth header that is only XOR-obfuscated, not signed...