CVE-2024-47066
- Reference to the description:
- Description:
- Lobe Chat is an open-source artificial intelligence chat framework. Prior to version 1.19.13, server-side request forgery protection implemented in `src/app/api/proxy/route.ts` does not consider redirect and could be bypassed when attacker provides an external malicious URL which redirects to internal resources like a private network or loopback address. Version 1.19.13 contains an improved fix for the issue.
- Last updated date:
- 09/30/2024
- Type:
- exploit
- Confidence:
- HIGH
- Date of publishing:
- 09/24/2024
- Reference url to background
- Type:
- exploit
- Confidence:
- HIGH
- Date of publishing:
- 09/30/2024
- Reference url to background
https://github.com/lobehub/lobe-chat/security/advisories/GHSA-3fc8-2r3f-8wrg