Executive brief
lobe-chat is a web-based chat interface and productivity application. The OIDC authentication redirect logic trusts X-Forwarded-* headers from reverse proxies without proper validation, allowing attackers to inject arbitrary hostnames and redirect users to malicious domains for phishing or credential harvesting attacks.
Technical details
The vulnerability is an open redirect (CWE-601) in the OIDC callback handler. The vulnerable code in the /oidc/consent route constructs the final redirect URL using the X-Forwarded-Host and X-Forwarded-Proto headers, trusting them without validation. An attacker can craft HTTP requests with malicious X-Forwarded-Host headers (e.g., `X-Forwarded-Host: google.com`) to trigger redirects to attacker-controlled domains. This requires user interaction (the user must click or follow the redirect) and network access to send the request. The attack is particularly effective in deployments where reverse proxies forward client-supplied headers as-is. The vulnerability is patched in version 1.130.1.
Affected products
- lobehub lobe-chat < 1.130.1
Timeline
- 2025-09-24: disclosed
- 2025-09-24: patched: Fixed in version 1.130.1
- 2025-09-25: other: CVE-2025-59426 published