Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2026-39411

30
FAUCET Score

BRIEFING NOTE: CVE-2026-39411 OVERVIEW LobeHub versions prior to 2.1.48 contain an authentication bypass vulnerability in the WebAPI layer. The system trusts a client-controlled X-lobe-chat-auth header that relies solely on XOR obfuscation with a hardcoded key stored in the public repository. This allows attackers to forge authentication tokens and bypass protections on critical API endpoints including chat providers, model retrieval, and image creation functions. SEVERITY The vulnerability carries a CVSS score of 7.1 (HIGH) with a network-based attack vector requiring minimal complexity and low privileges. The primary impact is integrity compromise, as attackers can manipulate API requests without authorization. While confidentiality impact is limited, the ability to forge authentication tokens across multiple sensitive endpoints presents significant risk to data integrity and service availability. The FAUCET risk score of 47.0 indicates moderate exploitability and potential for weaponization. EXPLOITATION STATUS The vulnerability is marked as active on threat tracking lists, indicating ongoing attention from security researchers and potential threat actors. The EPSS score of 0.00017 suggests exploitation probability remains relatively low but non-negligible. No public exploit code has been formally documented, though the hardcoded XOR key in the repository makes exploitation straightforward for technical actors. Organizations running affected versions should prioritize immediate patching to version 2.1.48 or later.

Impacted Technologies

VendorProductVersion(s)CPE
< 2.1.48CPE matchmatch criteria
cpe:2.3:a:lobehub:lobehub:*:*:*:*:*:node.js:*:*

CVSS Data

CVSS version used by this source: 3.1

5.0MEDIUM

CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:L

Attack Vector
NETWORK
Attack Complexity
HIGH
Privileges Required
LOW
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
LOW
Integrity Impact
LOW
Availability Impact
LOW
Exploitability Score
1.6
Impact Score
3.4
CvssVersion
3.1

Exploit Intelligence

EPSS Score
0.13%
Probability of exploitation in next 30 days
EPSS Percentile
2.6%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0013 is in the 0th percentile among its peer group of 17,823 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (2)

github_advisorypatch availablevia nvd_reference
View patch
npmpatch availablevia ghsa
Product: @lobehub/lobehubFixed in: 2.1.48

Vendor Advisories (1)

npmGHSA-5mwj-v5jw-5c97medium

LobeHub: Unauthenticated authentication bypass on `webapi` routes via forgeable `X-lobe-chat-auth` header

Apr 8, 2026

References

github.com / lobehub/lobehub/commit/3327b293d66c013f076cbc16cdbd05a61a3d0428
Patch
github.com / lobehub/lobehub/pull/13535
Issue Tracking
github.com / lobehub/lobehub/releases/tag/v2.1.48
Product
github.com / lobehub/lobehub/security/advisories/GHSA-5mwj-v5jw-5c97
Vendor Advisory