Vuln
·
Scope
Home
Packages
KEV
Critical
Insights
EN
中
Loading…
npm/@lobehub/chat — 11 CVEs · VulnScope
pkg:npm/
@lobehub/chat
11 total CVEs
CRITICAL
3
HIGH
1
MEDIUM
3
LOW
2
✅ Check your installed version
Check
All known vulnerabilities
CRITICAL
9.6
CVE-2026-23733
Lobe Chat affected by Cross-Site Scripting(XSS) that can escalate to Remote Code Execution(RCE)
from 0, <= 1.143.2
CRITICAL
9.0
CVE-2024-47066
lobe-chat implemented an insufficient fix for GHSA-mxhq-xw3g-rphc (CVE-2024-32964)
from 0, < 1.19.13
CRITICAL
9.0
CVE-2024-32964
lobe-chat `/api/proxy` endpoint Server-Side Request Forgery vulnerability
from 0, < 0.150.6
HIGH
8.1
@lobehub/chat Server Side Request Forgery vulnerability
from 0, < 1.19.13
MEDIUM
5.7
Lobe Chat API Key Leak
from 0, < 0.162.25
MEDIUM
5.3
@lobehub/chat vulnerable to unauthorized access to plugins
from 0, < 0.122.4
MEDIUM
4.3
lobe-chat has an Open Redirect
from 0, < 1.130.1
LOW
3.7
Lobe Chat has IDOR in Knowledge Base File Removal that Allows Cross User File Deletion
from 0, <= 1.143.2
LOW
3.0
Lobe Chat vulnerable to Server-Side Request Forgery with native web fetch module
from 0, < 1.136.2
—
LobeHub Vulnerable to Improper Authorization in Presigned Upload
from 0, < 1.143.3
—
Lobe Chat Desktop vulnerable to Remote Code Execution via XSS in Chat Messages
from 0, < 1.129.4
CVE-2024-32965
CVE-2024-37895
CVE-2024-24566
CVE-2025-59426
CVE-2026-23522
CVE-2025-62505
CVE-2026-23835
CVE-2025-59417