Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2026-85621— LobeChat 2.2.1 Webhook Signature Verification Bypass QQ Feishu

Quick assessment

Affected
lobehub lobehub
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

LobeChat (LobeHub) 2.2.1 未能在 QQ 和飞书适配器中正确验证入站聊天平台 Webhook 的签名。Webhook 路由(/api/agent/webhooks/:platform)在设计上未进行身份认证,并将签名验证工作委托给各个适配器;QQ 适配器在分发消息事件时未执行 Ed25519 签名验证,而飞书适配器仅执行可选的静态令牌比较——当未配置令牌时(默认情况)该步骤会被跳过,且这并非对请求体进行签名验证。知道公开 Webhook URL 的未认证攻击者可以发送带有攻击者选定的发送者身份

CVSS 6.5 · Medium

Possible ATT&CK Techniques 1 AI

T1190 · Exploit Public-Facing Application

Affected Version Matrix 1

VendorProduct Version RangeStatus
lobehub lobehub ≤ 2.2.15 affected
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-85621

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
LobeChat 2.2.1 Webhook Signature Verification Bypass QQ Feishu
Source: CVE Program / CVE List V5
Vulnerability Description
LobeChat (LobeHub) 2.2.1 does not properly verify inbound chat-platform webhook signatures in the QQ and Feishu adapters. The webhook route (/api/agent/webhooks/:platform) is unauthenticated by design and delegates verification to each adapter; the QQ adapter performs no Ed25519 signature verification on dispatched message events, and the Feishu adapter only performs an optional static-token comparison that is skipped when no token is configured (the default) and is not a body signature. An unauthenticated attacker who knows the public webhook URL can POST forged inbound messages with an attacker-chosen sender identity and arbitrary text, causing the bot owner's agent to process attacker-controlled input and treat the attacker as a trusted platform sender.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
Source: CVE Program / CVE List V5
Vulnerability Type
对数据真实性的验证不充分
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
lobehub lobehub 0 ~ 2.2.15 -

II. Public POCs for CVE-2026-85621

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-85621

登录查看更多情报信息。

Vendor Advisories for CVE-2026-85621 (1)

Vendor Pages for CVE-2026-85621 (1)

Other References for CVE-2026-85621 (1)

IV. Related Vulnerabilities

V. Comments for CVE-2026-85621

No comments yet


Leave a comment