Vulnerabilities/

@lobehub/chat vulnerable to unauthorized access to plugins

Severity:
Medium

Description

When the application is password-protected (deployed with the ACCESS_CODE option), it is possible to access plugins without proper authorization (without password).

Recommendation

Update the @lobehub/chat package to the latest compatible version. Followings are version details:

References

Related Issues

Tags:
npm
@lobehub/chat
Anything's wrong? Let us know Last updated on January 31, 2024

This issue is available in SmartScanner Professional

See Pricing