Lobehub develops a focused conversational AI platform, Lobe Chat, that sits in the application tier and handles authentication and request routing for language-model interactions. The vendor's vulnerabilities skew toward serious outcomes and frequently acquire public exploit code, concentrating across authentication and access-control weaknesses—including server-side request forgery, authentication bypass through spoofing, improper access control, and exposure of sensitive information—that reflect the security boundaries inherent to internet-facing chat and API gateway functionality. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Lobehub over time
Signals from CVEs in this vendor scope (13 CVEs).
13 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2024-32964CRITICAL Lobe Chat is a chatbot framework that supports speech synthesis, multimodal, and extensible Function Call plugin system. Prior to 0.150.6, lobe-chat had an unauthorized Server-Side | May 14, 2024 | 9.0 | 67 | NO | YES |
CVE-2026-59095HIGH LobeChat before 2.2.10-canary.18 contains a server-side request forgery vulnerability that allows authenticated attackers to direct internal HTTP requests to arbitrary URLs by supp | Jul 2, 2026 | 7.7 | 33 | NO | NO |
CVE-2024-32965HIGH Lobe Chat is an open-source, AI chat framework. Versions of lobe-chat prior to 1.19.13 have an unauthorized ssrf vulnerability. An attacker can construct malicious requests to caus | Nov 26, 2024 | 8.6 | 32 | NO | NO |
CVE-2024-47066HIGH Lobe Chat is an open-source artificial intelligence chat framework. Prior to version 1.19.13, server-side request forgery protection implemented in `src/app/api/proxy/route.ts` doe | Sep 23, 2024 | 8.8 | 32 | NO | NO |
CVE-2026-59098MEDIUM LobeChat through 2.2.9 contains a broken access control vulnerability in the retrieval-augmented-generation semantic search functionality that allows authenticated attackers to acc | Jul 2, 2026 | 6.5 | 31 | NO | NO |
CVE-2026-58578MEDIUM LobeChat before version 2.2.10-canary.15 contains a regular expression denial of service (ReDoS) vulnerability that allows authenticated attackers to block the Node.js event loop b | Jul 2, 2026 | 6.5 | 29 | NO | NO |
CVE-2026-58580MEDIUM LobeChat through 2.2.9 server-database deployments are vulnerable to broken object-level authorization in MessageModel. The updateMessagePlugin, updatePluginState, updatePluginErro | Jul 2, 2026 | 5.9 | 28 | NO | NO |
CVE-2026-39411HIGH LobeHub is a work-and-lifestyle space to find, build, and collaborate with agent teammates that grow with you. Prior to 2.1.48, the webapi authentication layer trusts a client-cont | Apr 8, 2026 | 7.1 | 28 | NO | NO |
CVE-2026-59100MEDIUM LobeChat through 2.2.9 contains a broken object level authorization vulnerability that allows authenticated attackers to access and modify other users' chat-group agent data by sup | Jul 2, 2026 | 5.0 | 27 | NO | NO |
CVE-2025-59417MEDIUM Lobe Chat is an open-source artificial intelligence chat framework. Prior to version 1.129.4, there is a a cross-site scripting (XSS) vulnerability when handling chat message in lo | Sep 18, 2025 | 6.1 | 21 | NO | NO |
Signals from CVEs in this vendor scope (13 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Lobehub.
Media articles that mention a CVE ID that affects a product developed by Lobehub — matched by CVE ID, not by vendor name.