Executive brief
LobeHub is an AI agent management platform that provides API endpoints for chat, model operations, and image generation. A flaw in the authentication mechanism allows unauthenticated attackers to forge authentication headers using a publicly available XOR key, bypassing login requirements and gaining access to protected API routes. This could allow attackers to use configured API credentials (like OpenAI keys) at the deployer's expense or impersonate legitimate users.
Technical details
The vulnerability is an authentication bypass caused by insufficient verification of client-supplied authentication data (CWE-287, CWE-345, CWE-290). The backend accepts an X-lobe-chat-auth header that is only XOR-obfuscated with a static hardcoded key ("LobeHub · LobeHub") found in the repository. The backend decodes this header and treats any truthy apiKey field as sufficient authentication without validating it against a real API key or session. An attacker with knowledge of the XOR key can craft forged payloads such as {"apiKey":"x"} or {"userId":"victim-user-123","apiKey":"x"} to access protected routes including POST /webapi/chat/[provider], GET /webapi/models/[provider], POST /webapi/models/[provider]/pull, and POST /webapi/create-image/comfyui. This requires network access but no prior authentication. The vulnerability was patched in version 2.1.48 by removing the XOR-based authentication mechanism entirely and requiring session/OIDC-based authentication instead.
Affected products
- LobeHub LobeHub <= 2.1.47
Timeline
- 2026-04-08: disclosed: Advisory GHSA-5mwj-v5jw-5c97 published
- 2026-04-07: patched: Fix merged in PR #13535, patched in v2.1.48