Impact
LobeChat up to version 2.2.9 contains a broken object‑level authorization flaw that allows an authenticated user to manipulate chat‑group agent data belonging to other users. By supplying an arbitrary group identifier to the getGroupAgents, updateAgentInGroup, or removeAgentsFromGroup endpoints, an attacker can read agent listings, alter agent roles and ordering, or delete agents from chat groups owned by other users. This results in unauthorized disclosure of conversation metadata and tampering of group configurations, compromising confidentiality and integrity of the affected data.
Affected Systems
The vulnerability affects all installations of LobeChat provided by lobehub up to and including version 2.2.9. No definitive information is available regarding fixes in newer releases; users should verify that they are running a patched version.
Risk and Exploitability
The CVSS score of 2.3 classifies the vulnerability as low severity, and the EPSS score of less than 1% indicates a very low likelihood of exploitation. The flaw is not listed in CISA’s KEV catalog. Exploitation requires only an authenticated session; an attacker can use an unowned group identifier to call the three vulnerable endpoints and read, re‑order, or delete another user’s agent data. Consequently, while the attack surface is limited, the impact on user data confidentiality and integrity remains significant for affected accounts.
OpenCVE Enrichment