CVE-2024-32964 is a critical Server-Side Request Forgery (SSRF) vulnerability affecting Lobe Chat versions prior to 0.150.6. This flaw allows an unauthenticated attacker to craft malicious requests to the /api/proxy endpoint, enabling them to access internal network services and potentially exfiltrate sensitive information. The vulnerability has a CVSS score of 9.0 (Critical), indicating a network-exploitable attack with low complexity and high impact on confidentiality, integrity, and availability. Its EPSS score of 0.675710000 suggests a high probability of exploitation. While there is no evidence of active exploitation in the wild (KEV: No), a Nuclei template for this SSRF vulnerability exists, indicating readily available exploit code. There is currently no significant community discussion or media coverage surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 0.150.6CPE matchmatch criteria | cpe:2.3:a:lobehub:lobe_chat:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:L/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.7 Bluesky, 0.4 Mastodon, and 1.7 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.4 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Insufficient fix for GHSA-mxhq-xw3g-rphc (CVE-2024-32964)
Sep 21, 2024Insufficient fix for GHSA-mxhq-xw3g-rphc (CVE-2024-32964)
Sep 21, 2024Insufficient fix for GHSA-mxhq-xw3g-rphc (CVE-2024-32964)
Sep 21, 2024Insufficient fix for GHSA-mxhq-xw3g-rphc (CVE-2024-32964)
Sep 21, 2024Insufficient fix for GHSA-mxhq-xw3g-rphc (CVE-2024-32964)
Sep 21, 2024Insufficient fix for GHSA-mxhq-xw3g-rphc (CVE-2024-32964)
Sep 21, 2024Insufficient fix for GHSA-mxhq-xw3g-rphc (CVE-2024-32964)
Sep 21, 2024lobe-chat `/api/proxy` endpoint Server-Side Request Forgery vulnerability
May 10, 2024