Lobe Chat is an open-source LLMs/AI chat framework. In affected versions if an attacker can successfully authenticate through SSO/Access Code, they can obtain the real backend API Key by modifying the base URL to their own attack URL on the frontend and setting up a server-side request. This issue has been addressed in version 0.162.25. Users are advised to upgrade. There are no known workarounds for this vulnerability.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-2115 | Lobe Chat is an open-source LLMs/AI chat framework. In affected versions if an attacker can successfully authenticate through SSO/Access Code, they can obtain the real backend API Key by modifying the base URL to their own attack URL on the frontend and setting up a server-side request. This issue has been addressed in version 0.162.25. Users are advised to upgrade. There are no known workarounds for this vulnerability. |
Github GHSA |
GHSA-p36r-qxgx-jq2v | Lobe Chat API Key Leak |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Wed, 08 Oct 2025 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:a:lobehub:lobe_chat:*:*:*:*:*:*:*:* |
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2024-08-02T03:57:39.976Z
Reserved: 2024-06-10T19:54:41.361Z
Link: CVE-2024-37895
Updated: 2024-06-18T14:05:13.719Z
Status : Analyzed
Published: 2024-06-17T20:15:13.970
Modified: 2025-10-08T16:08:51.550
Link: CVE-2024-37895
No data.
OpenCVE Enrichment
Updated: 2025-07-12T22:23:56Z
Weaknesses
EUVD
Github GHSA