CVE-2024-32964
Expert Analysis
Professional remediation guidance
Get tailored security recommendations from our analyst team for CVE-2024-32964. We'll provide specific mitigation strategies based on your environment and risk profile.
CVSS Score
V3.1EPSS Score
v2025.03.14There is a 24.5% chance that this vulnerability will be exploited in the wild within the next 30 days.
Attack Vector Metrics
Impact Metrics
Description
Lobe Chat is a chatbot framework that supports speech synthesis, multimodal, and extensible Function Call plugin system. Prior to 0.150.6, lobe-chat had an unauthorized Server-Side Request Forgery vulnerability in the /api/proxy endpoint. An attacker can construct malicious requests to cause Server-Side Request Forgery without logging in, attack intranet services, and leak sensitive information.
Available Exploits
Lobe Chat <= v0.150.5 - Server-Side Request Forgery
Lobe Chat is a chatbot framework that supports speech synthesis, multimodal, and extensible Function Call plugin system. Prior to 0.150.6, lobe-chat had an unauthorized Server-Side Request Forgery vulnerability in the /api/proxy endpoint. An attacker can construct malicious requests to cause Server-Side Request Forgery without logging in, attack intranet services, and leak sensitive information.
Related News
Affected Products
GitHub Security Advisories
Community-driven vulnerability intelligence from GitHub
lobe-chat `/api/proxy` endpoint Server-Side Request Forgery vulnerability
GHSA-mxhq-xw3g-rphcAdvisory Details
Affected Packages
CVSS Scoring
CVSS Score
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:L/A:H
References
Advisory provided by GitHub Security Advisory Database. Published: May 10, 2024, Modified: May 14, 2024