CVE-2026-54157

CRITICAL NUCLEI

LobeHub: Unauthenticated SSRF in `/webapi/proxy`

Title source: cna
STIX 2.1

Exploitation Summary

CVE-2026-54157 has a Nuclei detection template available — see the Nuclei card below for the Shodan/FOFA recon queries.

Description

LobeHub is a work-and-lifestyle space to find, build, and collaborate with agent teammates that grow with you. Prior to 2.1.57, the /webapi/proxy endpoint on app.lobehub.com accepts a URL in the POST body and fetches it server-side without any authentication. An attacker can use this to make arbitrary outbound requests from LobeHub's infrastructure, leak Vercel deployment details, and inject cookies on the lobehub.com domain through reflected Set-Cookie headers. This vulnerability is fixed in 2.1.57.

Nuclei Templates (1)

LobeHub LobeChat <= 2.1.56 - Server-Side Request Forgery
MEDIUMVERIFIEDby 0xj3st3r
FOFA: icon_hash="1975020705"

References (1)

Core 1
Core References

Scores

CVSS v3 9.0
EPSS 0.0178
EPSS Percentile 76.0%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:L/A:H

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact total

Details

CWE
CWE-918
Status published
Products (2)
lobehub/lobehub 0 - 2.1.57npm
lobehub/lobehub < 2.1.57
Published Jun 23, 2026
Tracked Since Jun 24, 2026