Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-r2cx-cpfx-9h63

Опубликовано: 02 июл. 2026
Источник: github
Github: Не прошло ревью
CVSS4: 8.3
CVSS3: 7.7

Описание

LobeChat before 2.2.10-canary.18 contains a server-side request forgery vulnerability that allows authenticated attackers to direct internal HTTP requests to arbitrary URLs by supplying user-controlled input to the skill import service (importFromUrl) and topic cover update (fetchImageFromUrl) endpoints, which use the global fetch without the project's ssrf-safe-fetch wrapper. Attackers can target internal addresses such as cloud instance metadata endpoints through these unprotected code paths to disclose internal service responses and cloud credentials.

LobeChat before 2.2.10-canary.18 contains a server-side request forgery vulnerability that allows authenticated attackers to direct internal HTTP requests to arbitrary URLs by supplying user-controlled input to the skill import service (importFromUrl) and topic cover update (fetchImageFromUrl) endpoints, which use the global fetch without the project's ssrf-safe-fetch wrapper. Attackers can target internal addresses such as cloud instance metadata endpoints through these unprotected code paths to disclose internal service responses and cloud credentials.

EPSS

Процентиль: 33%
0.00402
Низкий

8.3 High

CVSS4

7.7 High

CVSS3

Дефекты

CWE-918

Связанные уязвимости

CVSS3: 7.7
nvd
около 2 месяцев назад

LobeChat before 2.2.10-canary.18 contains a server-side request forgery vulnerability that allows authenticated attackers to direct internal HTTP requests to arbitrary URLs by supplying user-controlled input to the skill import service (importFromUrl) and topic cover update (fetchImageFromUrl) endpoints, which use the global fetch without the project's ssrf-safe-fetch wrapper. Attackers can target internal addresses such as cloud instance metadata endpoints through these unprotected code paths to disclose internal service responses and cloud credentials.

EPSS

Процентиль: 33%
0.00402
Низкий

8.3 High

CVSS4

7.7 High

CVSS3

Дефекты

CWE-918