Executive brief
LobeChat, an open-source AI chat framework, is vulnerable to a denial-of-service attack during the "skill import" process. An authenticated user can provide a specially crafted GitHub URL that causes the server to become unresponsive for nearly a minute per request. This can be used to block all other users from accessing the service, leading to significant operational downtime.
Technical details
A Regular Expression Denial of Service (ReDoS) vulnerability exists in the `agentSkills.importFromGitHub` tRPC endpoint. The root cause is the `findSkillMd` function in `src/server/services/skill/parser.ts`, which interpolates a user-controlled GitHub URL path segment (`basePath`) directly into a `new RegExp()` constructor without escaping. An authenticated attacker can provide a path containing catastrophic backtracking patterns (e.g., `(a+)+`). When the server processes the repository ZIP, the synchronous `.test()` call against archive entries blocks the Node.js event loop, denying service to all concurrent users. The vulnerability was fixed in version 2.2.10-canary.15 by replacing dynamic regex construction with plain string matching.
Affected products
- LobeHub LobeChat before 2.2.10-canary.15
Timeline
- 2026-05-18: disclosed: Initial private disclosure via GitHub Security Advisory
- 2026-06-30: disclosed: Public issue opened on GitHub repository
- 2026-07-01: patched: Fix merged into canary branch
- 2026-07-02: advisory: CVE published to NVD
References
- https://github.com/lobehub/lobehub/commit/349bbe326eb8635d6d9c6a96d12702681ae3a84a
- https://github.com/lobehub/lobehub/issues/16494
- https://github.com/lobehub/lobehub/pull/16548
- https://github.com/lobehub/lobehub/releases/tag/v2.2.10-canary.15
- https://www.vulncheck.com/advisories/lobechat-canary-15-regular-expression-denial-of-service-in-github-skill-import