File Upload Vulnerability in LobeHub Open Source Platform
CVE-2026-23835

5.7MEDIUM

Key Information:

Vendor

Lobehub

Status
Vendor
CVE Published:
30 January 2026

What is CVE-2026-23835?

LobeHub's file upload feature allows unauthorized users to bypass integrity checks before version 1.143.3, enabling the creation of files in unintended locations and manipulation of file size parameters. This inconsistency can mislead billing processes and result in excessive resource usage beyond intended limits. Such vulnerabilities can lead to significant service disruptions, ultimately affecting the user experience and operational stability by potentially causing denial of service for legitimate users.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.

Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.

Affected Version(s)

lobe-chat < 1.143.3

References

CVSS V4

Score:
5.7
Severity:
MEDIUM
Confidentiality:
None
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.