BRIEFING NOTE: CVE-2026-39411 OVERVIEW LobeHub versions prior to 2.1.48 contain an authentication bypass vulnerability in the WebAPI layer. The system trusts a client-controlled X-lobe-chat-auth header that relies solely on XOR obfuscation with a hardcoded key stored in the public repository. This allows attackers to forge authentication tokens and bypass protections on critical API endpoints including chat providers, model retrieval, and image creation functions. SEVERITY The vulnerability carries a CVSS score of 7.1 (HIGH) with a network-based attack vector requiring minimal complexity and low privileges. The primary impact is integrity compromise, as attackers can manipulate API requests without authorization. While confidentiality impact is limited, the ability to forge authentication tokens across multiple sensitive endpoints presents significant risk to data integrity and service availability. The FAUCET risk score of 47.0 indicates moderate exploitability and potential for weaponization. EXPLOITATION STATUS The vulnerability is marked as active on threat tracking lists, indicating ongoing attention from security researchers and potential threat actors. The EPSS score of 0.00017 suggests exploitation probability remains relatively low but non-negligible. No public exploit code has been formally documented, though the hardcoded XOR key in the repository makes exploitation straightforward for technical actors. Organizations running affected versions should prioritize immediate patching to version 2.1.48 or later.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 2.1.48CPE matchmatch criteria | cpe:2.3:a:lobehub:lobehub:*:*:*:*:*:node.js:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:L
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.