Description
Lobe Chat is a chatbot framework that supports speech synthesis, multimodal, and extensible Function Call plugin system. Prior to 0.150.6, lobe-chat had an unauthorized Server-Side Request Forgery vulnerability in the /api/proxy endpoint. An attacker can construct malicious requests to cause Server-Side Request Forgery without logging in, attack intranet services, and leak sensitive information.
Exploits (1)
nomisec
WORKING POC
1 stars
by StephenQSstarThomas · poc
https://github.com/StephenQSstarThomas/aaa-agentxploit-example
Nuclei Templates (1)
Lobe Chat <= v0.150.5 - Server-Side Request Forgery
CRITICALVERIFIEDby s4e-io
FOFA:
icon_hash="1975020705"
Scores
CVSS v3
9.0
EPSS
0.7414
EPSS Percentile
98.8%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:L/A:H
Lab Environment
COMMUNITY
Community Lab
Details
CWE
CWE-918
Status
published
Products (2)
lobehub/chat
0 - 0.150.6npm
lobehub/lobe_chat
< 0.150.6
Published
May 14, 2024
Tracked Since
Feb 18, 2026