Junglewise Threat Intelligence

CVE-2026-23522: Lobe Chat IDOR in Knowledge Base file removal

CVE-2026-23522 · Severity: low · CVSS 3.1 · Published 2026-01-20

Technologies: @lobehub/chat (npm). Vendors: npm.

Executive brief

Lobe Chat is an AI-powered application that uses Knowledge Bases to store documents for retrieval-augmented generation (RAG), which helps the AI provide more accurate and contextualized responses. A missing authorization check in the file deletion function allows an authenticated attacker to delete files from other users' Knowledge Bases if they know the target's Knowledge Base and file IDs, potentially causing loss of important documents and breaking RAG functionality.

Technical details

The vulnerability is an Insecure Direct Object Reference (IDOR) in the knowledgeBase.removeFilesFromKnowledgeBase tRPC endpoint caused by a commented-out userId filter in the database query. An authenticated attacker can craft a POST request to delete files from any Knowledge Base without verifying ownership. Attack requires knowledge of the target Knowledge Base ID and file ID, and network access to the tRPC endpoint. While IDs are randomly generated and not easily enumerable, they may leak through shared links, logs, or HTTP referrer headers. The patch is available in version v2.0.0-next.193.

Affected products

  • Lobe Lobe Chat <=v2.0.0-next.192

Timeline

  • 2026-01-20: disclosed
  • 2026-01-20: patched: patched in v2.0.0-next.193

References

Related threats