Junglewise Threat Intelligence

CVE-2024-32965: LobeHub Lobe Chat SSRF in OpenAI proxy configuration

CVE-2024-32965 · Severity: low · CVSS 3.1 · Published 2024-11-26

Technologies: LobeHub Lobe Chat, @lobehub/chat (npm). Vendors: LobeHub, npm.

Executive brief

Lobe Chat is an open-source framework for building AI-powered chat interfaces. A security flaw allows unauthenticated attackers to trick the server into making unauthorized requests to internal network services. This could lead to the exposure of sensitive internal data or allow attackers to probe private infrastructure that is not normally accessible from the internet.

Technical details

A Server-Side Request Forgery (SSRF) vulnerability exists in Lobe Chat due to insufficient validation of the proxy address provided in the 'X-Lobe-Chat-Auth' header. An unauthenticated attacker can provide a malicious proxy endpoint (e.g., using a loopback address or internal IP) which the server will then attempt to contact to fulfill chat requests. By manipulating the JWT token in the header, an attacker can bypass intended restrictions to scan internal networks or leak sensitive information from intranet services. The vulnerability is addressed in version 1.19.13 by implementing improved SSRF protections.

Affected products

  • LobeHub lobe-chat < 1.19.13

Timeline

  • 2024-11-26: advisory: GitHub Security Advisory published
  • 2024-11-26: patched: Fixed in version 1.19.13

References

Related threats