Arvin Xu
8 exploits
Active since Jan 2024
lobehub/lobe_chat < 0.150.6 - Unauthenticated Server-Side Request Forgery via /api/proxy Endpoint
CVSS 9.0
lobehub/lobe_chat < 1.19.13 - Server-Side Request Forgery via Redirect Bypass
CVSS 9.0
LobeHub <2.1.48 webapi Routes - Authentication Bypass
CVSS 5.0
lobehub/lobe_chat < 0.122.4 - Unauthenticated Plugin Access via Improper Access Control
CVSS 5.3
lobehub/lobe_chat < 1.19.13 - Unauthenticated Server-Side Request Forgery via JWT Token Header
CVSS 8.1
lobehub/lobe_chat < 1.129.4 - Cross-Site Scripting via SVG Rendering
CVSS 6.1
lobehub/lobe_chat < 1.130.1 - Open Redirect via X-Forwarded-Host Header
CVSS 4.3
LobeChat <2.0.0-next.193 - Privilege Escalation
CVSS 3.7