Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Lobehub

First CVE: Jan 31, 2024Active for: 2 yearsTotal CVEs: 13
48.7
VTI Score
High

Lobehub develops a focused conversational AI platform, Lobe Chat, that sits in the application tier and handles authentication and request routing for language-model interactions. The vendor's vulnerabilities skew toward serious outcomes and frequently acquire public exploit code, concentrating across authentication and access-control weaknesses—including server-side request forgery, authentication bypass through spoofing, improper access control, and exposure of sensitive information—that reflect the security boundaries inherent to internet-facing chat and API gateway functionality. Current severity, exploitation activity, and exposure counts are shown alongside this summary.

FAUCET AI Generated
13
Total CVEs
More Total CVEs than 94% of tracked vendors
2.2
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 89% of tracked vendors
6.7
Avg CVSS Score
Higher Avg CVSS Score than 43% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Lobehub over time

Volume of CVEsAvg CVSS Base Score
First CVE
Jan 31, 2024
2 years ago
Most Recent CVE
Jul 2, 2026
21 days ago

Products(2 total)

Top CVEs

Signals from CVEs in this vendor scope (13 CVEs).

13 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2024-32964CRITICAL
Lobe Chat is a chatbot framework that supports speech synthesis, multimodal, and extensible Function Call plugin system. Prior to 0.150.6, lobe-chat had an unauthorized Server-Side
May 14, 20249.067NOYES
CVE-2026-59095HIGH
LobeChat before 2.2.10-canary.18 contains a server-side request forgery vulnerability that allows authenticated attackers to direct internal HTTP requests to arbitrary URLs by supp
Jul 2, 20267.733NONO
CVE-2024-32965HIGH
Lobe Chat is an open-source, AI chat framework. Versions of lobe-chat prior to 1.19.13 have an unauthorized ssrf vulnerability. An attacker can construct malicious requests to caus
Nov 26, 20248.632NONO
CVE-2024-47066HIGH
Lobe Chat is an open-source artificial intelligence chat framework. Prior to version 1.19.13, server-side request forgery protection implemented in `src/app/api/proxy/route.ts` doe
Sep 23, 20248.832NONO
CVE-2026-59098MEDIUM
LobeChat through 2.2.9 contains a broken access control vulnerability in the retrieval-augmented-generation semantic search functionality that allows authenticated attackers to acc
Jul 2, 20266.531NONO
CVE-2026-58578MEDIUM
LobeChat before version 2.2.10-canary.15 contains a regular expression denial of service (ReDoS) vulnerability that allows authenticated attackers to block the Node.js event loop b
Jul 2, 20266.529NONO
CVE-2026-58580MEDIUM
LobeChat through 2.2.9 server-database deployments are vulnerable to broken object-level authorization in MessageModel. The updateMessagePlugin, updatePluginState, updatePluginErro
Jul 2, 20265.928NONO
CVE-2026-39411HIGH
LobeHub is a work-and-lifestyle space to find, build, and collaborate with agent teammates that grow with you. Prior to 2.1.48, the webapi authentication layer trusts a client-cont
Apr 8, 20267.128NONO
CVE-2026-59100MEDIUM
LobeChat through 2.2.9 contains a broken object level authorization vulnerability that allows authenticated attackers to access and modify other users' chat-group agent data by sup
Jul 2, 20265.027NONO
CVE-2025-59417MEDIUM
Lobe Chat is an open-source artificial intelligence chat framework. Prior to version 1.129.4, there is a a cross-site scripting (XSS) vulnerability when handling chat message in lo
Sep 18, 20256.121NONO
View all 13 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products13 CVEs
62%
31%
Severity distribution among all CVEs352,101 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network13 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low11 (84.6%)
High2 (15.4%)
Unknown0 (0.0%)
User Interaction
None10 (76.9%)
Unknown0 (0.0%)
Required3 (23.1%)
Privileges Required
Low8 (61.5%)
High1 (7.7%)
None4 (30.8%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (13 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
1 CVE
7.7% of CVEs· 96th percentile
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Lobehub.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Lobehub — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Lobehub's Products

View all 2 CNAs →

Top CWEs