Junglewise Threat Intelligence

CVE-2025-59426: lobe-chat open redirect via X-Forwarded-Host header

CVE-2025-59426 · Severity: low · CVSS 3.1 · Published 2025-09-24

Technologies: LobeHub Lobe Chat, @lobehub/chat (npm). Vendors: LobeHub, npm.

Executive brief

lobe-chat is a web-based chat interface and productivity application. The OIDC authentication redirect logic trusts X-Forwarded-* headers from reverse proxies without proper validation, allowing attackers to inject arbitrary hostnames and redirect users to malicious domains for phishing or credential harvesting attacks.

Technical details

The vulnerability is an open redirect (CWE-601) in the OIDC callback handler. The vulnerable code in the /oidc/consent route constructs the final redirect URL using the X-Forwarded-Host and X-Forwarded-Proto headers, trusting them without validation. An attacker can craft HTTP requests with malicious X-Forwarded-Host headers (e.g., `X-Forwarded-Host: google.com`) to trigger redirects to attacker-controlled domains. This requires user interaction (the user must click or follow the redirect) and network access to send the request. The attack is particularly effective in deployments where reverse proxies forward client-supplied headers as-is. The vulnerability is patched in version 1.130.1.

Affected products

  • lobehub lobe-chat < 1.130.1

Timeline

  • 2025-09-24: disclosed
  • 2025-09-24: patched: Fixed in version 1.130.1
  • 2025-09-25: other: CVE-2025-59426 published

References

Related threats