Lobe Chat是一个开源、高性能的聊天机器人框架。 Lobe Chat 0.150.6之前版本存在安全漏洞,该漏洞源于存在未经授权的服务器端请求伪造漏洞,攻击者无需登录即可构造恶意请求导致服务器端请求伪造和泄露敏感信息。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
10-question deep dive: root cause, exploitation, mitigation, urgency. Read summary free, full version requires login.
| # | POC Description | Source Link | Shenlong Link |
|---|---|---|---|
| 1 | Lobe Chat is a chatbot framework that supports speech synthesis, multimodal, and extensible Function Call plugin system. Prior to 0.150.6, lobe-chat had an unauthorized Server-Side Request Forgery vulnerability in the /api/proxy endpoint. An attacker can construct malicious requests to cause Server-Side Request Forgery without logging in, attack intranet services, and leak sensitive information. | https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2024/CVE-2024-32964.yaml | POC Details |
| 2 | examplar proj. aaa-cve-2024-32964-ssrf | https://github.com/StephenQSstarThomas/aaa-agentxploit-example | POC Details |
No comments yet