CVE-2024-47066
Last modified
CVE-2024-47066 is a high-severity vulnerability rated 8.8/10 on the CVSS scale. Lobe Chat is an open-source artificial intelligence chat framework. Prior to version 1.19.13, server-side request forgery protection implemented in `src/app/api/proxy/route.ts` does not consider redirect and could be bypassed when attacker provides an external malicious URL which redirects to internal resources like a private network or loopback address. EPSS estimates a 10.79% chance of exploitation in the next 30 days.
Description
Lobe Chat is an open-source artificial intelligence chat framework. Prior to version 1.19.13, server-side request forgery protection implemented in `src/app/api/proxy/route.ts` does not consider redirect and could be bypassed when attacker provides an external malicious URL which redirects to internal resources like a private network or loopback address. Version 1.19.13 contains an improved fix for the issue.
Metrics
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Lobehub | Lobe Chat | < 1.19.3 |
References
- https://github.com/lobehub/lobe-chat/security/advisories/GHSA-3fc8-2r3f-8wrgExploit, Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2024-47066?
How severe is CVE-2024-47066?
How do I fix CVE-2024-47066?
Are you affected by CVE-2024-47066?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
