Server-side Request Forgery in LobeHub Affecting User Data
CVE-2026-54157

9CRITICAL

Key Information:

Vendor

Lobehub

Status
Vendor
CVE Published:
23 June 2026

What is CVE-2026-54157?

The LobeHub application features a critical vulnerability in its /webapi/proxy endpoint, where unauthenticated POST requests can be made to fetch arbitrary URLs. This flaw allows attackers to exploit LobeHub’s infrastructure, potentially leaking sensitive deployment information and enabling cookie injections via reflected Set-Cookie headers. Users running versions prior to 2.1.57 are particularly at risk, emphasizing the importance of upgrading to mitigate these threats.

Affected Version(s)

lobehub < 2.1.57

References

CVSS V3.1

Score:
9
Severity:
CRITICAL
Confidentiality:
High
Integrity:
Low
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.