Executive brief
Lobe Chat is an open-source conversational AI platform. An authenticated attacker can steal backend API credentials by changing the base URL setting to point to an attacker-controlled server and intercepting the API key from request headers. This allows an attacker with valid user credentials to obtain secrets needed to directly access the backend API, potentially enabling unauthorized AI service usage or data exfiltration.
Technical details
The vulnerability is a Server-Side Request Forgery (SSRF) coupled with credential exposure (CWE-918, CWE-200). Lobe Chat permits authenticated users to modify the backend base URL without validating or restricting outbound destinations. When a user configures a malicious URL and triggers a server-side request, the backend leaks its API key in request headers sent to the attacker's controlled server. The attack requires prior SSO/Access Code authentication and user interaction to change the configuration. No outbound traffic whitelist is implemented. The vulnerability affects all community versions up to 0.162.24; a patch is available in 0.162.25.
Affected products
- Lobe Hub Lobe Chat <=0.162.24
Timeline
- 2024-06-17: disclosed: GHSA-p36r-qxgx-jq2v published
- 2024-06-17: patched: Fix released in version 0.162.25