Vulnerabilities/

lobe-chat implemented an insufficient fix for GHSA-mxhq-xw3g-rphc (CVE-2024-32964)

Severity:
Medium

Description

SSRF protection implemented in https://github.com/lobehub/lobe-chat/blob/main/src/app/api/proxy/route.ts does not consider redirect and could be bypassed when attacker provides external malicious url which redirects to internal resources like private network or loopback address.

Recommendation

Update the @lobehub/chat package to the latest compatible version. Followings are version details:

References

Related Issues

Tags:
npm
@lobehub/chat
Anything's wrong? Let us know Last updated on September 30, 2024

This issue is available in SmartScanner Professional

See Pricing