← Vulnerability feed

Vulnerability record · CVE-2024-24566 · published 31 January 2024

CVE-2024-24566: Lobehub lobe chat improper access control vulnerability

Lobehub · Lobe Chat

Lobe Chat is a chatbot framework that supports speech synthesis, multimodal, and extensible Function Call plugin system. When the application is password-protected (deployed with the `ACCESS_CODE` option), it is possible to access plugins without proper authorization (without password). This vulnerability is patched in 0.122.4.

5.3 CVSS 3.1 Medium EPSS 0.48% · top 60.9% CWE-284 · Improper access control
5.3CVSS 3.1 base score
0.48%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
4References, 2 tagged exploit
17 Jun 2026Last modified by NVD

Description

Lobe Chat is a chatbot framework that supports speech synthesis, multimodal, and extensible Function Call plugin system. When the application is password-protected (deployed with the `ACCESS_CODE` option), it is possible to access plugins without proper authorization (without password). This vulnerability is patched in 0.122.4.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2024-24566 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.0CVE-2024-32964Lobe Chat /api/proxy endpoint unauthenticated SSRFLobe Chat versions prior to 0.150.6 contain a server-side request forgery flaw in the /api/proxy endpoint. The description states the endpoint can be…EPSS 53%analysed8.8CVE-2024-47066Lobehub lobe chat server-side request forgery (ssrf) vulnerabilityLobe Chat is an open-source artificial intelligence chat framework. Prior to version 1.19.13, server-side request forgery protection implemented in `…EPSS 12%8.6CVE-2024-32965Lobehub lobe chat server-side request forgery (ssrf) vulnerabilityLobe Chat is an open-source, AI chat framework. Versions of lobe-chat prior to 1.19.13 have an unauthorized ssrf vulnerability. An attacker can const…EPSS 28%6.8CVE-2025-59417Lobehub lobe chat cross-site scripting vulnerabilityLobe Chat is an open-source artificial intelligence chat framework. Prior to version 1.129.4, there is a a cross-site scripting (XSS) vulnerability w…EPSS 0.40%5.7CVE-2024-37895Lobehub lobe chat information exposure vulnerabilityLobe Chat is an open-source LLMs/AI chat framework. In affected versions if an attacker can successfully authenticate through SSO/Access Code, they c…EPSS 0.55%4.3CVE-2025-59426Lobehub lobe chat open redirect vulnerabilityLobe Chat is an open-source artificial intelligence chat framework. Prior to version 1.130.1, the project's OIDC redirect handling logic constructs t…EPSS 0.32%7.8CVE-2026-81963Windows Update Stack link-following privilege escalationWindows Update Stack resolves links improperly before accessing files, a link-following flaw (CWE-59) compounded by improper access control (CWE-284)…KEVEPSS 0.39%analysed10.0CVE-2026-21962Oracle HTTP Server and WebLogic Proxy Plug-in improper access controlOracle HTTP Server and the WebLogic Server Proxy Plug-in (for Apache HTTP Server and IIS) contain an improper access control flaw (CWE-284) in suppor…KEVEPSS 71%analysed

Source: NIST National Vulnerability Database (record CVE-2024-24566), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.