Vulnerabilidades em lobehub

19 resultados
Análise Vexday

O LobHub apresenta 19 vulnerabilidades conhecidas, com 7 publicadas nos últimos 90 dias, indicando atividade recente no escopo do produto. Nenhuma vulnerabilidade está sob ataque ativo (KEV), e apenas 3 atingem severidade crítica, reduzindo o risco imediato. A fraqueza dominante é CWE-918 (SSRF - Server-Side Request Forgery), típica de aplicações web, demandando atenção em controles de acesso a recursos internos.

CVE-2024-32964CRITICALlobe-chat `/api/proxy` endpoint Server-Side Request Forgery vulnerabilityEPSS 52.7%CVE-2024-32965HIGHssrf vulnerability in lobe-chatEPSS 23.9%CVE-2024-47066CRITICALLobe Chat has insufficient fix for GHSA-mxhq-xw3g-rphc (CVE-2024-32964)EPSS 11.8%CVE-2026-54157CRITICALLobeHub: Unauthenticated SSRF in `/webapi/proxy`EPSS 1.8%CVE-2024-37895MEDIUMAPI Key Leak in lobe-chatEPSS 0.5%CVE-2024-24566MEDIUMLobe Chat unauthorized access to pluginsEPSS 0.5%CVE-2025-59417MEDIUMLobe Chat Desktop Vulnerable to Remote Code Execution via XSS in Chat MessagesEPSS 0.4%CVE-2026-23835MEDIUMLobeHub Vulnerable to Improper Authorization in Presigned UploadEPSS 0.3%CVE-2026-58578HIGHLobeChat < 2.2.10-canary.15 - Regular Expression Denial of Service in GitHub Skill ImportEPSS 0.3%CVE-2025-59426MEDIUMlobe-chat has an Open RedirectEPSS 0.3%CVE-2025-62505LOWSSRF in lobehub/lobe-chat with native web fetch moduleEPSS 0.3%CVE-2026-42045MEDIUMLobeHub: Cross-Site Scripting(XSS) escalate to Remote Code Execution(RCE)EPSS 0.3%CVE-2026-59098HIGHLobeChat 2.2.9 - Cross-User Document Disclosure via Unscoped RAG Semantic SearchEPSS 0.2%CVE-2026-59095HIGHLobeChat < 2.2.10-canary.18 - SSRF via importFromUrl and fetchImageFromUrlEPSS 0.2%CVE-2026-23522LOWLobe Chat has IDOR in Knowledge Base File Removal that Allows Cross User File DeletionEPSS 0.2%CVE-2026-59100LOWLobeChat 2.2.9 - Broken Object Level Authorization via Chat-Group Agent OperationsEPSS 0.2%CVE-2026-58580MEDIUMLobeChat 2.2.9 - Broken Object-Level Authorization in Message Sub-Resource WritesEPSS 0.2%CVE-2026-39411MEDIUMLobeHub has an unauthenticated authentication bypass on `webapi` routes via forgeable `X-lobe-chat-auth` headerEPSS 0.1%CVE-2026-23733MEDIUMLobe Chat has Cross-Site Scripting (XSS) issue that may escalate to Remote Code Execution (RCE)EPSS 0.1%