Server-side Request Forgery in LobeHub Affecting User Data
CVE-2026-54157
9CRITICAL
What is CVE-2026-54157?
The LobeHub application features a critical vulnerability in its /webapi/proxy endpoint, where unauthenticated POST requests can be made to fetch arbitrary URLs. This flaw allows attackers to exploit LobeHub’s infrastructure, potentially leaking sensitive deployment information and enabling cookie injections via reflected Set-Cookie headers. Users running versions prior to 2.1.57 are particularly at risk, emphasizing the importance of upgrading to mitigate these threats.
Affected Version(s)
lobehub < 2.1.57
