CVE-2024-47066: lobe-chat implemented an insufficient fix for GHSA-mxhq-xw3g-rphc (CVE-2024-32964)
(updated )
SSRF protection implemented in https://github.com/lobehub/lobe-chat/blob/main/src/app/api/proxy/route.ts does not consider redirect and could be bypassed when attacker provides external malicious url which redirects to internal resources like private network or loopback address.
References
- github.com/advisories/GHSA-3fc8-2r3f-8wrg
- github.com/lobehub/lobe-chat
- github.com/lobehub/lobe-chat/blob/main/src/app/api/proxy/route.ts
- github.com/lobehub/lobe-chat/commit/e960a23b0c69a5762eb27d776d33dac443058faf
- github.com/lobehub/lobe-chat/security/advisories/GHSA-3fc8-2r3f-8wrg
- github.com/lobehub/lobe-chat/security/advisories/GHSA-mxhq-xw3g-rphc
- nvd.nist.gov/vuln/detail/CVE-2024-47066
Detect and mitigate CVE-2024-47066 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →