Junglewise Threat Intelligence

CVE-2026-58580: LobeHub LobeChat broken object-level authorization in MessageModel

CVE-2026-58580 · Severity: medium · CVSS 5.9 · Published 2026-07-02

Technologies: LobeHub LobeChat. Vendors: LobeHub.

Executive brief

LobeChat, an open-source AI chat framework, contains a security flaw in its multi-user server deployments. An authenticated user can modify another person's chat data—including plugin settings, text-to-speech records, and translations—if they know the specific ID of the victim's message. This could allow an attacker to tamper with a victim's conversation history or inject malicious tool-call metadata, though the attack is difficult to perform because message IDs are not easily guessable.

Technical details

LobeChat's MessageModel implementation contains a Broken Object-Level Authorization (BOLA) vulnerability (CWE-639). Specifically, the updateMessagePlugin, updatePluginState, updatePluginError, updateTTS, and updateTranslate methods filter database rows using only the message ID, failing to include the 'userId' scope required for multi-tenant isolation. An authenticated attacker can reach these methods via tRPC procedures and overwrite a victim's plugin tool-call metadata, state, text-to-speech, or translation records. Because the findMessagePlugin method also lacks user-scoping, the tampered content is served back to the victim. Exploitation is limited by the requirement that the attacker must obtain the victim's non-enumerable 12-character message identifier (nanoid).

Affected products

  • LobeHub LobeChat through 2.2.9

Timeline

  • 2026-06-04: disclosed: Private disclosure to vendor via GitHub Security Advisory
  • 2026-07-02: advisory: Public disclosure and NVD publication

References

Related threats