Vulnerability record · CVE-2024-32964 · published 14 May 2024
CVE-2024-32964: Lobe Chat /api/proxy endpoint unauthenticated SSRF
Lobehub · Lobe Chat
Lobe Chat versions prior to 0.150.6 contain a server-side request forgery flaw in the /api/proxy endpoint. The description states the endpoint can be reached without logging in, allowing crafted requests to make the server fetch attacker-chosen URLs. This exposes internal network services and can leak sensitive information.
Description
Lobe Chat is a chatbot framework that supports speech synthesis, multimodal, and extensible Function Call plugin system. Prior to 0.150.6, lobe-chat had an unauthorized Server-Side Request Forgery vulnerability in the /api/proxy endpoint. An attacker can construct malicious requests to cause Server-Side Request Forgery without logging in, attack intranet services, and leak sensitive information.
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:L/A:H
Automated analysis
critical priorityCVSS 9.0 critical with unauthenticated network reachability, high EPSS, and a vendor advisory tagged Exploit make this an urgent exposure for internet-facing Lobe Chat instances.
What it is
Lobe Chat versions prior to 0.150.6 contain a server-side request forgery flaw in the /api/proxy endpoint. The description states the endpoint can be reached without logging in, allowing crafted requests to make the server fetch attacker-chosen URLs. This exposes internal network services and can leak sensitive information.
Impact
An attacker can force the Lobe Chat server to issue requests to internal or otherwise unreachable services, enabling intranet reconnaissance and exfiltration of sensitive data returned through the proxy. The CVSS vector also indicates high confidentiality and availability impact.
Attack surface
Reachable over the network via the /api/proxy HTTP endpoint. The description explicitly states no login is required, and the CVSS vector shows no user interaction (UI:N).
Exploitation
Not listed in CISA KEV and no ransomware association is documented. EPSS is high (0.52964, 98.9th percentile), and the vendor advisory is tagged Exploit, indicating public exploit detail exists.
What to do
- Upgrade Lobe Chat to 0.150.6 or later, applying the referenced patch commit.
- If immediate upgrade is not possible, block or disable the /api/proxy endpoint at the reverse proxy or application layer.
- Restrict outbound network access from the Lobe Chat host to only required destinations, denying access to internal RFC1918 ranges and metadata endpoints.
- Place Lobe Chat behind authentication and network controls so the proxy endpoint is not exposed to untrusted networks.
Detection
- Monitor /api/proxy request logs for URLs pointing to internal IP ranges, localhost, or cloud metadata addresses such as 169.254.169.254.
- Alert on unusual outbound connections originating from the Lobe Chat server to internal services.
- Review proxy responses for signs of internal service data being returned to external clients.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2024-32964 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2024-32964), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.