CVE-2026-58580
Last modified
CVE-2026-58580 is a medium-severity vulnerability rated 6/10 on the CVSS scale. LobeChat through 2.2.9 server-database deployments are vulnerable to broken object-level authorization in MessageModel. The updateMessagePlugin, updatePluginState, updatePluginError, updateTTS and updateTranslate methods filter target rows by message id alone, omitting the userId scope that sibling methods apply, and findMessagePlugin reads back by id alone. EPSS estimates a 0.15% chance of exploitation in the next 30 days.
Description
LobeChat through 2.2.9 server-database deployments are vulnerable to broken object-level authorization in MessageModel. The updateMessagePlugin, updatePluginState, updatePluginError, updateTTS and updateTranslate methods filter target rows by message id alone, omitting the userId scope that sibling methods apply, and findMessagePlugin reads back by id alone. Reachable via the corresponding tRPC message procedures, an authenticated user who knows another user's message identifier can overwrite that victim's plugin tool-call metadata, plugin state/error, text-to-speech and translation records on the same instance, and the tampered content is served back to the victim. Exploitation requires knowledge of the victim's non-enumerable message identifier.
Metrics
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:H/A:N
CVSS:4.0/AV:N/AC:H/AT:N/PR:L/UI:N/VC:L/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Weakness Enumeration
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| lobehub | lobehub | <= 2.2.9 |
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2026-58580?
How severe is CVE-2026-58580?
How do I fix CVE-2026-58580?
How Strix Helps
- Uncovering a hidden BOLA in Appsmith's snapshot logicStrix autonomously discovered a BOLA/IDOR vulnerability in Appsmith's snapshot deletion path.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-58559DoS vulnerability in the vibration service. Impact: Successf…6.5
- CVE-2026-5856Contiki-NG's DNS/mDNS resolver skip_name() in os/services/re…7.1
- CVE-2026-5857Contiki-NG's MQTT client parse_publish_vhdr() in os/net/app-…9.2
- CVE-2026-58578LobeChat before version 2.2.10-canary.15 contains a regular …7.1
- CVE-2026-58579RAGFlow before 0.26.3 stores an agent pipeline (DSL) node na…5.4
- CVE-2026-5858Heap buffer overflow in WebML in Google Chrome prior to 147.…8.8
- CVE-2026-58583FluxInk (formerly Sunia SPB Peripheral) Color Management Dri…8.4
- CVE-2026-58586Image::WebP versions before 0.3.0 for Perl bundle a vulnerab…9.8
- CVE-2026-58587Improper Neutralization of Input During Web Page Generation …6.1
- CVE-2026-58588Improper Neutralization of Input During Web Page Generation …6.1
- CVE-2026-58589Missing Authorization vulnerability in Drupal FlowDrop allow…5.4
- CVE-2026-5859Integer overflow in WebML in Google Chrome prior to 147.0.77…8.8
Are you affected by CVE-2026-58580?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
