Junglewise Threat Intelligence

CVE-2026-59100: LobeHub LobeChat broken object level authorization in chat-group agents

CVE-2026-59100 · Severity: medium · CVSS 5 · Published 2026-07-02

Technologies: LobeHub LobeChat. Vendors: LobeHub.

Executive brief

LobeChat, an open-source AI chat framework, contains a security flaw in how it handles chat group permissions. An authenticated user can view, modify, or delete the AI agents assigned to chat groups belonging to other users by guessing or obtaining their group IDs. This could lead to unauthorized access to private group configurations, disruption of service, or tampering with how AI agents behave for other users.

Technical details

A Broken Object Level Authorization (BOLA) vulnerability, also known as Insecure Direct Object Reference (IDOR), exists in LobeChat's database repository layer. Specifically, the 'getGroupAgents', 'updateAgentInGroup', and 'removeAgentsFromGroup' operations in the ChatGroupModel and AgentGroupRepository fail to include a userId predicate in their SQL/ORM queries. An authenticated attacker can exploit this by sending crafted tRPC requests containing arbitrary UUIDs for group identifiers. This allows the attacker to bypass ownership checks to read agent listings, modify agent roles and ordering, or remove agents from groups belonging to other users. The issue was addressed by adding ownership scoping (userId and workspaceId) to the affected database queries.

Affected products

  • LobeHub LobeChat through 2.2.9

Timeline

  • 2026-06-04: disclosed: Initial researcher report to vendor
  • 2026-07-01: patched: Fix merged in GitHub PR 16586
  • 2026-07-02: advisory: CVE published and NVD entry created

References

Related threats