CVE Feed

    Dashboard / CVE / CVE-2024-47066

    CVE-2024-47066

    Lobe Chat is an open-source artificial intelligence chat framework. Prior to version 1.19.13, server-side request forgery protection implemented in `src/app/api/proxy/route.ts` does not consider redirect and could be bypassed when attacker provides an external malicious URL which redirects to internal resources like a private network or loopback address. Version 1.19.13 contains an improved fix for the issue.

    Published:Sep 23, 2024
    Last Modified:Sep 30, 2024
    EPS:Sep 23, 2024
    EPSS Score:0.0451
    CVSS Score:9

    Affected Products

    Vendor
    Lobehub
    Product
    Lobe Chat

    Common Attack Pattern Enumeration and Classification (CAPEC)

    Related CVEs

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High