Executive brief
LobeChat, an open-source AI chat framework, contains a security flaw in its multi-user server deployments. An authenticated user can modify another person's chat data—including plugin settings, text-to-speech records, and translations—if they know the specific ID of the victim's message. This could allow an attacker to tamper with a victim's conversation history or inject malicious tool-call metadata, though the attack is difficult to perform because message IDs are not easily guessable.
Technical details
LobeChat's MessageModel implementation contains a Broken Object-Level Authorization (BOLA) vulnerability (CWE-639). Specifically, the updateMessagePlugin, updatePluginState, updatePluginError, updateTTS, and updateTranslate methods filter database rows using only the message ID, failing to include the 'userId' scope required for multi-tenant isolation. An authenticated attacker can reach these methods via tRPC procedures and overwrite a victim's plugin tool-call metadata, state, text-to-speech, or translation records. Because the findMessagePlugin method also lacks user-scoping, the tampered content is served back to the victim. Exploitation is limited by the requirement that the attacker must obtain the victim's non-enumerable 12-character message identifier (nanoid).
Affected products
- LobeHub LobeChat through 2.2.9
Timeline
- 2026-06-04: disclosed: Private disclosure to vendor via GitHub Security Advisory
- 2026-07-02: advisory: Public disclosure and NVD publication