Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2024-32964

67
FAUCET Score

CVE-2024-32964 is a critical Server-Side Request Forgery (SSRF) vulnerability affecting Lobe Chat versions prior to 0.150.6. This flaw allows an unauthenticated attacker to craft malicious requests to the /api/proxy endpoint, enabling them to access internal network services and potentially exfiltrate sensitive information. The vulnerability has a CVSS score of 9.0 (Critical), indicating a network-exploitable attack with low complexity and high impact on confidentiality, integrity, and availability. Its EPSS score of 0.675710000 suggests a high probability of exploitation. While there is no evidence of active exploitation in the wild (KEV: No), a Nuclei template for this SSRF vulnerability exists, indicating readily available exploit code. There is currently no significant community discussion or media coverage surrounding this CVE.

Impacted Technologies

VendorProductVersion(s)CPE
< 0.150.6CPE matchmatch criteria
cpe:2.3:a:lobehub:lobe_chat:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

9.0CRITICAL

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:L/A:H

Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
HIGH
User Interaction
NONE
Scope
CHANGED
Confidentiality Impact
HIGH
Integrity Impact
LOW
Availability Impact
HIGH
Exploitability Score
2.3
Impact Score
6.0
CvssVersion
3.1

Exploit Intelligence

EPSS Score
52.68%
Probability of exploitation in next 30 days
EPSS Percentile
98.9%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
Nuclei: CVE-2024-32964 · Oct 1, 2024
This CVE's current EPSS score of 0.5268 is in the 99th percentile among its peer group of 464 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.7 Bluesky, 0.4 Mastodon, and 1.7 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.4 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (9)

github_advisorypatch availablevia nvd_reference
View patch
npmpatch availablevia ghsa
Product: @lobehub/chatFixed in: 0.150.6
puppetpatch availablevia llm_extracted
View patch
honovendor investigatingvia llm_extracted
intelvendor investigatingvia llm_extracted
lobehubvendor investigatingvia llm_extracted
mariadbvendor investigatingvia llm_extracted
navidromevendor investigatingvia llm_extracted
View patch
railsvendor investigatingvia llm_extracted

Vendor Advisories (8)

navidromellm-navidrome-e15f888647920e20CRITICAL

Insufficient fix for GHSA-mxhq-xw3g-rphc (CVE-2024-32964)

Sep 21, 2024
mariadbllm-mariadb-574e78e68d9c76bcCRITICAL

Insufficient fix for GHSA-mxhq-xw3g-rphc (CVE-2024-32964)

Sep 21, 2024
intelllm-intel-24ac87501c2ee682CRITICAL

Insufficient fix for GHSA-mxhq-xw3g-rphc (CVE-2024-32964)

Sep 21, 2024
honollm-hono-b3b0f837b1fd1bebCRITICAL

Insufficient fix for GHSA-mxhq-xw3g-rphc (CVE-2024-32964)

Sep 21, 2024
puppetllm-puppet-7022ddb273054f06CRITICAL

Insufficient fix for GHSA-mxhq-xw3g-rphc (CVE-2024-32964)

Sep 21, 2024
railsllm-rails-d555d6de2e9585d3CRITICAL

Insufficient fix for GHSA-mxhq-xw3g-rphc (CVE-2024-32964)

Sep 21, 2024
lobehubllm-lobehub-a24e490565dbbc49CRITICAL

Insufficient fix for GHSA-mxhq-xw3g-rphc (CVE-2024-32964)

Sep 21, 2024
npmGHSA-mxhq-xw3g-rphccritical

lobe-chat `/api/proxy` endpoint Server-Side Request Forgery vulnerability

May 10, 2024

References

github.com / lobehub/lobe-chat/commit/465665a735556669ee30446c7ea9049a20cc7c37
Patch
github.com / lobehub/lobe-chat/security/advisories/GHSA-mxhq-xw3g-rphc
ExploitVendor Advisory