Advisory Database
  • Advisories
  • Dependency Scanning
  1. npm
  2. ›
  3. @lobehub/chat
  4. ›
  5. CVE-2024-47066

CVE-2024-47066: lobe-chat implemented an insufficient fix for GHSA-mxhq-xw3g-rphc (CVE-2024-32964)

September 23, 2024 (updated September 30, 2024)

SSRF protection implemented in https://github.com/lobehub/lobe-chat/blob/main/src/app/api/proxy/route.ts does not consider redirect and could be bypassed when attacker provides external malicious url which redirects to internal resources like private network or loopback address.

References

  • github.com/advisories/GHSA-3fc8-2r3f-8wrg
  • github.com/lobehub/lobe-chat
  • github.com/lobehub/lobe-chat/blob/main/src/app/api/proxy/route.ts
  • github.com/lobehub/lobe-chat/commit/e960a23b0c69a5762eb27d776d33dac443058faf
  • github.com/lobehub/lobe-chat/security/advisories/GHSA-3fc8-2r3f-8wrg
  • github.com/lobehub/lobe-chat/security/advisories/GHSA-mxhq-xw3g-rphc
  • nvd.nist.gov/vuln/detail/CVE-2024-47066

Code Behaviors & Features

Detect and mitigate CVE-2024-47066 with GitLab Dependency Scanning

Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →

Affected versions

All versions before 1.19.13

Fixed versions

  • 1.19.13

Solution

Upgrade to version 1.19.13 or above.

Impact 8.8 HIGH

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Learn more about CVSS

Weakness

  • CWE-918: Server-Side Request Forgery (SSRF)

Source file

npm/@lobehub/chat/CVE-2024-47066.yml

Spotted a mistake? Edit the file on GitLab.

  • Site Repo
  • About GitLab
  • Terms
  • Privacy Statement
  • Contact

Page generated Tue, 13 May 2025 12:14:48 +0000.