Description
Lobe Chat is a chatbot framework that supports speech synthesis, multimodal, and extensible Function Call plugin system. When the application is password-protected (deployed with the `ACCESS_CODE` option), it is possible to access plugins without proper authorization (without password). This vulnerability is patched in 0.122.4.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-0393 | Lobe Chat is a chatbot framework that supports speech synthesis, multimodal, and extensible Function Call plugin system. When the application is password-protected (deployed with the `ACCESS_CODE` option), it is possible to access plugins without proper authorization (without password). This vulnerability is patched in 0.122.4. |
Github GHSA |
GHSA-pf55-fj96-xf37 | @lobehub/chat vulnerable to unauthorized access to plugins |
References
History
Tue, 17 Jun 2025 22:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2025-06-17T21:29:21.984Z
Reserved: 2024-01-25T15:09:40.210Z
Link: CVE-2024-24566
Updated: 2024-08-01T23:19:52.946Z
Status : Modified
Published: 2024-01-31T17:15:39.173
Modified: 2024-11-21T08:59:26.090
Link: CVE-2024-24566
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD
Github GHSA