Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2026-54157

Опубликовано: 23 июн. 2026
Источник: nvd
CVSS3: 9
EPSS Низкий

Описание

LobeHub is a work-and-lifestyle space to find, build, and collaborate with agent teammates that grow with you. Prior to 2.1.57, the /webapi/proxy endpoint on app.lobehub.com accepts a URL in the POST body and fetches it server-side without any authentication. An attacker can use this to make arbitrary outbound requests from LobeHub's infrastructure, leak Vercel deployment details, and inject cookies on the lobehub.com domain through reflected Set-Cookie headers. This vulnerability is fixed in 2.1.57.

EPSS

Процентиль: 76%
0.01782
Низкий

9 Critical

CVSS3

Дефекты

CWE-918

Связанные уязвимости

CVSS3: 9
github
около 2 месяцев назад

LobeHub: Unauthenticated SSRF in `/webapi/proxy`

EPSS

Процентиль: 76%
0.01782
Низкий

9 Critical

CVSS3

Дефекты

CWE-918