File Upload Vulnerability in LobeHub Open Source Platform
CVE-2026-23835
5.7MEDIUM
What is CVE-2026-23835?
LobeHub's file upload feature allows unauthorized users to bypass integrity checks before version 1.143.3, enabling the creation of files in unintended locations and manipulation of file size parameters. This inconsistency can mislead billing processes and result in excessive resource usage beyond intended limits. Such vulnerabilities can lead to significant service disruptions, ultimately affecting the user experience and operational stability by potentially causing denial of service for legitimate users.
Affected Version(s)
lobe-chat < 1.143.3
