{"id":"CVE-2024-32964","summary":"lobe-chat `/api/proxy` endpoint Server-Side Request Forgery vulnerability","details":"Lobe Chat is a chatbot framework that supports speech synthesis, multimodal, and extensible Function Call plugin system. Prior to 0.150.6, lobe-chat had an unauthorized Server-Side Request Forgery vulnerability in the /api/proxy endpoint. An attacker can construct malicious requests to cause Server-Side Request Forgery without logging in, attack intranet services, and leak sensitive information.","aliases":["GHSA-mxhq-xw3g-rphc"],"modified":"2026-04-29T04:12:12.130189Z","published":"2024-05-10T14:49:31.019Z","database_specific":{"unresolved_ranges":[{"extracted_events":[{"last_affected":"0.150.5"}],"source":"AFFECTED_FIELD"}],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2024/32xxx/CVE-2024-32964.json","cwe_ids":["CWE-918"],"cna_assigner":"GitHub_M"},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2024/32xxx/CVE-2024-32964.json"},{"type":"ADVISORY","url":"https://github.com/lobehub/lobe-chat/security/advisories/GHSA-mxhq-xw3g-rphc"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2024-32964"},{"type":"FIX","url":"https://github.com/lobehub/lobe-chat/commit/465665a735556669ee30446c7ea9049a20cc7c37"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/lobehub/lobe-chat","events":[{"introduced":"0"},{"fixed":"752e0a3ba24303c43a5217a5d5447eb90ff2e598"}],"database_specific":{"versions":[{"introduced":"0"},{"fixed":"0.150.6"}]}},{"type":"GIT","repo":"https://github.com/lobehub/lobehub","events":[{"introduced":"0"},{"fixed":"465665a735556669ee30446c7ea9049a20cc7c37"}]}],"versions":["v0.1.5","v0.10.0","v0.10.1","v0.10.2","v0.100.0","v0.100.1","v0.100.2","v0.100.3","v0.100.4","v0.100.5","v0.101.0","v0.101.1","v0.101.2","v0.101.3","v0.101.4","v0.101.5","v0.101.6","v0.101.7","v0.102.0","v0.102.1","v0.102.2","v0.102.3","v0.102.4","v0.103.0","v0.103.1","v0.104.0","v0.105.0","v0.105.1","v0.105.2","v0.106.0","v0.107.0","v0.107.1","v0.107.10","v0.107.11","v0.107.12","v0.107.13","v0.107.14","v0.107.15","v0.107.16","v0.107.2","v0.107.3","v0.107.4","v0.107.5","v0.107.6","v0.107.7","v0.107.8","v0.107.9","v0.108.0","v0.109.0","v0.109.1","v0.11.0","v0.110.0","v0.110.1","v0.110.10","v0.110.2","v0.110.3","v0.110.4","v0.110.5","v0.110.6","v0.110.7","v0.110.8","v0.110.9","v0.111.0","v0.111.1","v0.111.2","v0.111.3","v0.111.4","v0.111.5","v0.111.6","v0.112.0","v0.112.1","v0.113.0","v0.113.1","v0.114.0","v0.114.1","v0.114.2","v0.114.3","v0.114.4","v0.114.5","v0.114.6","v0.114.7","v0.114.8","v0.114.9","v0.115.0","v0.115.1","v0.115.10","v0.115.11","v0.115.12","v0.115.13","v0.115.2","v0.115.3","v0.115.4","v0.115.5","v0.115.6","v0.115.7","v0.115.8","v0.115.9","v0.116.0","v0.116.1","v0.116.2","v0.116.3","v0.116.4","v0.116.5","v0.117.0","v0.117.1","v0.117.2","v0.117.3","v0.117.4","v0.117.5","v0.118.0","v0.118.1","v0.118.10","v0.118.2","v0.118.3","v0.118.4","v0.118.5","v0.118.6","v0.118.7","v0.118.8","v0.118.9","v0.119.0","v0.119.1","v0.119.10","v0.119.11","v0.119.12","v0.119.13","v0.119.2","v0.119.3","v0.119.4","v0.119.5","v0.119.6","v0.119.7","v0.119.8","v0.119.9","v0.12.0","v0.12.1","v0.120.0","v0.120.1","v0.120.2","v0.120.3","v0.120.4","v0.120.5","v0.120.6","v0.121.0","v0.121.1","v0.121.2","v0.121.3","v0.121.4","v0.122.0","v0.122.1","v0.122.2","v0.122.3","v0.122.4","v0.122.5","v0.122.6","v0.122.7","v0.122.8","v0.122.9","v0.123.0","v0.123.1","v0.123.2","v0.123.3","v0.123.4","v0.124.0","v0.124.1","v0.124.2","v0.124.3","v0.125.0","v0.126.0","v0.126.1","v0.126.2","v0.126.3","v0.126.4","v0.126.5","v0.127.0","v0.127.1","v0.127.2","v0.128.0","v0.128.1","v0.128.10","v0.128.2","v0.128.3","v0.128.4","v0.128.5","v0.128.6","v0.128.7","v0.128.8","v0.128.9","v0.129.0","v0.129.1","v0.129.2","v0.129.3","v0.129.4","v0.129.5","v0.129.6","v0.13.0","v0.13.1","v0.130.0","v0.130.1","v0.130.2","v0.130.3","v0.130.4","v0.130.5","v0.130.6","v0.130.7","v0.131.0","v0.132.0","v0.132.1","v0.132.2","v0.133.0","v0.133.1","v0.133.2","v0.133.3","v0.133.4","v0.133.5","v0.134.0","v0.134.1","v0.135.0","v0.135.1","v0.135.2","v0.135.3","v0.135.4","v0.136.0","v0.137.0","v0.138.0","v0.138.1","v0.138.2","v0.139.0","v0.139.1","v0.139.2","v0.14.0","v0.140.0","v0.140.1","v0.141.0","v0.141.1","v0.141.2","v0.142.0","v0.142.1","v0.142.2","v0.142.3","v0.142.4","v0.142.5","v0.142.6","v0.142.7","v0.142.8","v0.142.9","v0.143.0","v0.144.0","v0.144.1","v0.145.0","v0.145.1","v0.145.10","v0.145.11","v0.145.12","v0.145.13","v0.145.2","v0.145.3","v0.145.4","v0.145.5","v0.145.6","v0.145.7","v0.145.8","v0.145.9","v0.146.0","v0.146.1","v0.146.2","v0.147.0","v0.147.1","v0.147.10","v0.147.11","v0.147.12","v0.147.13","v0.147.14","v0.147.15","v0.147.16","v0.147.17","v0.147.18","v0.147.19","v0.147.2","v0.147.20","v0.147.21","v0.147.22","v0.147.3","v0.147.4","v0.147.5","v0.147.6","v0.147.7","v0.147.8","v0.147.9","v0.148.0","v0.148.1","v0.148.10","v0.148.2","v0.148.3","v0.148.4","v0.148.5","v0.148.6","v0.148.7","v0.148.8","v0.148.9","v0.149.0","v0.149.1","v0.149.2","v0.149.3","v0.149.4","v0.149.5","v0.149.6","v0.15.0","v0.15.1","v0.150.0","v0.150.1","v0.150.2","v0.150.3","v0.150.4","v0.150.5","v0.16.0","v0.16.1","v0.17.0","v0.18.0","v0.18.1","v0.18.2","v0.19.0","v0.2.0","v0.20.0","v0.21.0","v0.22.0","v0.22.1","v0.22.2","v0.23.0","v0.25.0","v0.26.0","v0.26.1","v0.27.0","v0.27.1","v0.27.2","v0.27.3","v0.27.4","v0.28.0","v0.29.0","v0.3.0","v0.30.0","v0.30.1","v0.31.0","v0.32.0","v0.33.0","v0.35.0","v0.35.1","v0.36.0","v0.36.1","v0.37.0","v0.38.0","v0.39.0","v0.39.1","v0.39.2","v0.39.3","v0.4.0","v0.4.2","v0.4.3","v0.40.0","v0.40.1","v0.40.2","v0.40.3","v0.40.4","v0.40.5","v0.40.6","v0.40.7","v0.41.0","v0.41.1","v0.41.2","v0.42.0","v0.42.1","v0.42.2","v0.42.3","v0.43.0","v0.44.0","v0.44.1","v0.44.2","v0.44.3","v0.44.4","v0.46.0","v0.46.1","v0.47.0","v0.48.0","v0.49.0","v0.5.0","v0.50.0","v0.51.0","v0.52.0","v0.52.1","v0.53.0","v0.54.0","v0.54.1","v0.54.2","v0.54.3","v0.54.4","v0.55.0","v0.55.1","v0.56.0","v0.57.0","v0.58.0","v0.59.0","v0.6.0","v0.6.1","v0.60.0","v0.60.1","v0.60.2","v0.60.3","v0.60.4","v0.61.0","v0.62.0","v0.62.1","v0.63.0","v0.63.1","v0.63.2","v0.63.3","v0.64.0","v0.64.1","v0.65.0","v0.65.1","v0.66.0","v0.67.0","v0.68.0","v0.68.1","v0.69.0","v0.69.1","v0.7.0","v0.70.0","v0.70.1","v0.70.2","v0.70.3","v0.70.4","v0.71.0","v0.71.1","v0.72.0","v0.72.1","v0.72.2","v0.72.3","v0.72.4","v0.73.0","v0.74.0","v0.75.0","v0.76.0","v0.76.1","v0.76.2","v0.77.0","v0.77.1","v0.77.2","v0.78.0","v0.78.1","v0.79.0","v0.79.1","v0.79.2","v0.79.3","v0.79.4","v0.79.5","v0.79.6","v0.79.7","v0.79.8","v0.8.0","v0.8.1","v0.8.2","v0.80.0","v0.80.1","v0.80.2","v0.81.0","v0.82.0","v0.82.1","v0.82.2","v0.82.3","v0.82.4","v0.82.5","v0.82.6","v0.82.7","v0.82.8","v0.82.9","v0.83.0","v0.83.1","v0.83.10","v0.83.2","v0.83.3","v0.83.4","v0.83.5","v0.83.6","v0.83.7","v0.83.8","v0.83.9","v0.84.0","v0.85.0","v0.85.1","v0.85.2","v0.85.3","v0.86.0","v0.86.1","v0.86.2","v0.86.3","v0.86.4","v0.86.5","v0.87.0","v0.88.0","v0.89.0","v0.89.1","v0.89.10","v0.89.2","v0.89.3","v0.89.4","v0.89.5","v0.89.6","v0.89.7","v0.89.8","v0.89.9","v0.9.0","v0.90.0","v0.90.1","v0.90.2","v0.90.3","v0.91.0","v0.92.0","v0.93.0","v0.94.0","v0.94.1","v0.94.2","v0.94.3","v0.94.4","v0.94.5","v0.95.0","v0.95.1","v0.96.0","v0.96.1","v0.96.2","v0.96.3","v0.96.4","v0.96.5","v0.96.6","v0.96.7","v0.96.8","v0.96.9","v0.97.0","v0.97.1","v0.98.0","v0.98.1","v0.98.2","v0.98.3","v0.99.0","v0.99.1","v1.0.0"],"database_specific":{"source":"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2024-32964.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:L/A:H"}]}