GHSA-mxhq-xw3g-rphc
CRITICALCVE-2024-32964SSRF protection implemented in https://github.com/lobehub/lobe-chat/blob/main/src/app/api/proxy/route.ts does not consider redirect and could be bypassed when attacker provides external malicious url which redirects to internal resources like private network or loopback address.
- Affected
- >=0, <1.19.13
- Fixed in
- 0.150.6
- Weakness
- CWE-918
- Published
- 2024-05-10
- Source
- github