← Vulnerability feed

Vulnerability record · CVE-2025-59426 · published 25 September 2025

CVE-2025-59426: Lobehub lobe chat open redirect vulnerability

Lobehub · Lobe Chat

Lobe Chat is an open-source artificial intelligence chat framework. Prior to version 1.130.1, the project's OIDC redirect handling logic constructs the host and protocol of the final redirect URL based on the X-Forwarded-Host or Host headers and the X-Forwarded-Proto value. In deployments where a reverse proxy forwards client-supplied X-Forwarded-* headers to the origin as-is, or where the origin trusts them without validation, an attacker can inject an arbitrary host and trigger an open redirect that sends users to a malicious domain. This issue has been patched in version 1.130.1.

4.3 CVSS 3.1 Medium EPSS 0.32% · top 77.2% CWE-601 · Open redirect
4.3CVSS 3.1 base score
0.32%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
4References, 2 tagged exploit
17 Jun 2026Last modified by NVD

Description

Lobe Chat is an open-source artificial intelligence chat framework. Prior to version 1.130.1, the project's OIDC redirect handling logic constructs the host and protocol of the final redirect URL based on the X-Forwarded-Host or Host headers and the X-Forwarded-Proto value. In deployments where a reverse proxy forwards client-supplied X-Forwarded-* headers to the origin as-is, or where the origin trusts them without validation, an attacker can inject an arbitrary host and trigger an open redirect that sends users to a malicious domain. This issue has been patched in version 1.130.1.

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2025-59426 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.0CVE-2024-32964Lobe Chat /api/proxy endpoint unauthenticated SSRFLobe Chat versions prior to 0.150.6 contain a server-side request forgery flaw in the /api/proxy endpoint. The description states the endpoint can be…EPSS 53%analysed8.8CVE-2024-47066Lobehub lobe chat server-side request forgery (ssrf) vulnerabilityLobe Chat is an open-source artificial intelligence chat framework. Prior to version 1.19.13, server-side request forgery protection implemented in `…EPSS 12%8.6CVE-2024-32965Lobehub lobe chat server-side request forgery (ssrf) vulnerabilityLobe Chat is an open-source, AI chat framework. Versions of lobe-chat prior to 1.19.13 have an unauthorized ssrf vulnerability. An attacker can const…EPSS 28%6.8CVE-2025-59417Lobehub lobe chat cross-site scripting vulnerabilityLobe Chat is an open-source artificial intelligence chat framework. Prior to version 1.129.4, there is a a cross-site scripting (XSS) vulnerability w…EPSS 0.40%5.7CVE-2024-37895Lobehub lobe chat information exposure vulnerabilityLobe Chat is an open-source LLMs/AI chat framework. In affected versions if an attacker can successfully authenticate through SSO/Access Code, they c…EPSS 0.55%5.3CVE-2024-24566Lobehub lobe chat improper access control vulnerabilityLobe Chat is a chatbot framework that supports speech synthesis, multimodal, and extensible Function Call plugin system. When the application is pass…EPSS 0.48%4.7CVE-2012-0518Oracle Fusion Middleware SSO open redirect flawOracle Fusion Middleware 10.1.4.3.0 contains an unspecified open redirect vulnerability in the Application Server Single Sign-On component, tracked a…KEVEPSS 4.7%analysed6.1CVE-2021-38000Google Chrome Android Intents input validation open redirectChrome on Android before 95.0.4638.69 fails to properly validate untrusted input passed through Intents, allowing a crafted HTML page to redirect the…KEVEPSS 4.9%analysed

Source: NIST National Vulnerability Database (record CVE-2025-59426), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.