CVE-2026-54157
CRITICAL NUCLEILobeHub: Unauthenticated SSRF in `/webapi/proxy`
Title source: cnaExploitation Summary
CVE-2026-54157 has a Nuclei detection template available — see the Nuclei card below for the Shodan/FOFA recon queries.
Description
LobeHub is a work-and-lifestyle space to find, build, and collaborate with agent teammates that grow with you. Prior to 2.1.57, the /webapi/proxy endpoint on app.lobehub.com accepts a URL in the POST body and fetches it server-side without any authentication. An attacker can use this to make arbitrary outbound requests from LobeHub's infrastructure, leak Vercel deployment details, and inject cookies on the lobehub.com domain through reflected Set-Cookie headers. This vulnerability is fixed in 2.1.57.
Nuclei Templates (1)
LobeHub LobeChat <= 2.1.56 - Server-Side Request Forgery
MEDIUMVERIFIEDby 0xj3st3r
FOFA:
icon_hash="1975020705"
References (1)
Core 1
Core References
X_Refsource_Confirm x_refsource_confirm
https://github.com/lobehub/lobehub/security/advisories/GHSA-xmwj-c75x-6346
Scores
CVSS v3
9.0
EPSS
0.0178
EPSS Percentile
76.0%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:L/A:H
CISA SSVC
Vulnrichment
Exploitation
poc
Automatable
no
Technical Impact
total
Details
CWE
CWE-918
Status
published
Products (2)
lobehub/lobehub
0 - 2.1.57npm
lobehub/lobehub
< 2.1.57
Published
Jun 23, 2026
Tracked Since
Jun 24, 2026