Description
No description available.
Recommendation
Update the @lobehub/lobehub package to the latest compatible version. Followings are version details:
- Affected version(s): <= 2.1.56
- Patched version(s): 2.1.57
References
Related Issues
- LobeHub: Unauthenticated authentication bypass on `webapi` routes via forgeable `X-lobe-chat-auth` header - CVE-2026-39411
- SillyTavern has a SSRF vulnerability in the CORS proxy middleware - CVE-2026-44652
- SillyTavern: SSRF in SearXNG Search Proxy via Unvalidated baseUrl - CVE-2026-46372
- Neotoma: Unauthenticated Inspector/API access via reverse-proxy loopback auth bypass - CVE-2026-45577
You might also like:
- Tags:
- npm
- @lobehub/lobehub
Anything's wrong? Let us know Last updated on July 20, 2026


