Junglewise Threat Intelligence

CVE-2024-24566: LobeHub Lobe Chat authentication bypass in plugin gateway

CVE-2024-24566 · Severity: low · CVSS 3.1 · Published 2024-01-31

Technologies: LobeHub Lobe Chat, @lobehub/chat (npm). Vendors: LobeHub, npm.

Executive brief

Lobe Chat is an open-source chat application that can be deployed with password protection to control access. A vulnerability allows attackers to bypass this password protection and directly invoke chat plugins through the `/api/plugin/gateway` endpoint without entering the required access code. This enables unauthorized users to interact with integrated services and potentially access sensitive functionality that should be restricted.

Technical details

The vulnerability is an improper access control flaw (CWE-284) in Lobe Chat versions up to 0.122.3. When the application is deployed with the ACCESS_CODE environment variable to enable password protection, the authentication check is not enforced on the `/api/plugin/gateway` API endpoint. An unauthenticated attacker can craft HTTP POST requests directly to this endpoint and invoke any available plugin (such as WeatherGPT) without providing the required access code. The attack requires only network access and no user interaction. The fix, available in version 0.122.4, adds proper ACCESS_CODE verification to the plugin gateway route.

Affected products

  • LobeHub Lobe Chat up to 0.122.3

Timeline

  • 2024-01-31: disclosed: Advisory published
  • 2024-01-31: patched: Fix released in version 0.122.4

References

Related threats