Impact
LobeChat before 2.2.10‑canary.18 allows authenticated users to submit any URL to the importFromUrl and fetchImageFromUrl endpoints. These APIs use the global fetch function without the project’s ssrf‑safe to issue internal HTTP requests. An attacker can target internal services, such as cloud instance metadata endpoints, and read their responses, potentially revealing sensitive data like credentials. The vulnerability is classified as a CWE‑918 SSRF flaw.
Affected Systems
The affected product is LobeChat by Lobehub. All installations of LobeChat older than version 2.2.10‑canary.18 are susceptible until the vulnerability is fixed or the endpoints are disabled.
Risk and Exploitability
The CVSS score of 8.3 highlights a high risk of internal data disclosure. With an EPSS score of less than 1%, the exploit probability in the wild is low, and the flaw is not currently listed in the CISA KEV catalog. Exploitation requires the attacker to be authenticated to a LobeChat instance; once authenticated, the attacker can direct internal HTTP requests to arbitrary endpoints reachable from the host, potentially leaking confidential information and enabling further compromise.
OpenCVE Enrichment