← Vulnerability feed

Vulnerability record · CVE-2024-32964 · published 14 May 2024

CVE-2024-32964: Lobe Chat /api/proxy endpoint unauthenticated SSRF

Lobehub · Lobe Chat

Lobe Chat versions prior to 0.150.6 contain a server-side request forgery flaw in the /api/proxy endpoint. The description states the endpoint can be reached without logging in, allowing crafted requests to make the server fetch attacker-chosen URLs. This exposes internal network services and can leak sensitive information.

9.0 CVSS 3.1 Critical EPSS 53% · top 1.1% CWE-918 · Server-side request forgery (SSRF)
9.0CVSS 3.1 base score
53%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
4References, 2 tagged exploit
17 Jun 2026Last modified by NVD

Description

Lobe Chat is a chatbot framework that supports speech synthesis, multimodal, and extensible Function Call plugin system. Prior to 0.150.6, lobe-chat had an unauthorized Server-Side Request Forgery vulnerability in the /api/proxy endpoint. An attacker can construct malicious requests to cause Server-Side Request Forgery without logging in, attack intranet services, and leak sensitive information.

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:L/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 20 September 2026. Confidence: high.

critical priorityCVSS 9.0 critical with unauthenticated network reachability, high EPSS, and a vendor advisory tagged Exploit make this an urgent exposure for internet-facing Lobe Chat instances.

What it is

Lobe Chat versions prior to 0.150.6 contain a server-side request forgery flaw in the /api/proxy endpoint. The description states the endpoint can be reached without logging in, allowing crafted requests to make the server fetch attacker-chosen URLs. This exposes internal network services and can leak sensitive information.

Impact

An attacker can force the Lobe Chat server to issue requests to internal or otherwise unreachable services, enabling intranet reconnaissance and exfiltration of sensitive data returned through the proxy. The CVSS vector also indicates high confidentiality and availability impact.

Attack surface

Reachable over the network via the /api/proxy HTTP endpoint. The description explicitly states no login is required, and the CVSS vector shows no user interaction (UI:N).

Exploitation

Not listed in CISA KEV and no ransomware association is documented. EPSS is high (0.52964, 98.9th percentile), and the vendor advisory is tagged Exploit, indicating public exploit detail exists.

What to do

  • Upgrade Lobe Chat to 0.150.6 or later, applying the referenced patch commit.
  • If immediate upgrade is not possible, block or disable the /api/proxy endpoint at the reverse proxy or application layer.
  • Restrict outbound network access from the Lobe Chat host to only required destinations, denying access to internal RFC1918 ranges and metadata endpoints.
  • Place Lobe Chat behind authentication and network controls so the proxy endpoint is not exposed to untrusted networks.

Detection

  • Monitor /api/proxy request logs for URLs pointing to internal IP ranges, localhost, or cloud metadata addresses such as 169.254.169.254.
  • Alert on unusual outbound connections originating from the Lobe Chat server to internal services.
  • Review proxy responses for signs of internal service data being returned to external clients.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2024-32964 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

8.8CVE-2024-47066Lobehub lobe chat server-side request forgery (ssrf) vulnerabilityLobe Chat is an open-source artificial intelligence chat framework. Prior to version 1.19.13, server-side request forgery protection implemented in `…EPSS 12%8.6CVE-2024-32965Lobehub lobe chat server-side request forgery (ssrf) vulnerabilityLobe Chat is an open-source, AI chat framework. Versions of lobe-chat prior to 1.19.13 have an unauthorized ssrf vulnerability. An attacker can const…EPSS 28%6.8CVE-2025-59417Lobehub lobe chat cross-site scripting vulnerabilityLobe Chat is an open-source artificial intelligence chat framework. Prior to version 1.129.4, there is a a cross-site scripting (XSS) vulnerability w…EPSS 0.40%5.7CVE-2024-37895Lobehub lobe chat information exposure vulnerabilityLobe Chat is an open-source LLMs/AI chat framework. In affected versions if an attacker can successfully authenticate through SSO/Access Code, they c…EPSS 0.55%5.3CVE-2024-24566Lobehub lobe chat improper access control vulnerabilityLobe Chat is a chatbot framework that supports speech synthesis, multimodal, and extensible Function Call plugin system. When the application is pass…EPSS 0.48%4.3CVE-2025-59426Lobehub lobe chat open redirect vulnerabilityLobe Chat is an open-source artificial intelligence chat framework. Prior to version 1.130.1, the project's OIDC redirect handling logic constructs t…EPSS 0.32%10.0CVE-2026-83548SonicWall SMA1000 pre-auth SSRF via alternate access pathThe SMA1000 Appliance Work Place interface exposes an unintended alternate access path that allows server-side request forgery before authentication.…KEVEPSS 8.8%analysed10.0CVE-2026-49869Kestra OSS auth bypass via path suffix match enables RCEKestra OSS AuthenticationFilter whitelists the public config endpoint using request.getPath().endsWith("/configs"), a suffix match instead of an exac…KEVEPSS 2.1%analysed

Source: NIST National Vulnerability Database (record CVE-2024-32964), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.