Arvin Xu
6 exploits
Active since Jan 2024
LobeHub has an unauthenticated authentication bypass on `webapi` routes via forgeable `X-lobe-chat-auth` header
CVSS 5.0
Lobe Chat <0.122.4 - Auth Bypass
CVSS 5.3
Lobehub Lobe Chat < 1.19.13 - SSRF
CVSS 8.1
Lobehub Lobe Chat < 1.129.4 - XSS
CVSS 6.1
Lobehub Lobe Chat < 1.130.1 - Open Redirect
CVSS 4.3
LobeChat <2.0.0-next.193 - Privilege Escalation
CVSS 3.7