{"id":"CVE-2024-47066","summary":"Lobe Chat has insufficient fix for GHSA-mxhq-xw3g-rphc (CVE-2024-32964)","details":"Lobe Chat is an open-source artificial intelligence chat framework. Prior to version 1.19.13, server-side request forgery protection implemented in `src/app/api/proxy/route.ts` does not consider redirect and could be bypassed when attacker provides an external malicious URL which redirects to internal resources like a private network or loopback address. Version 1.19.13 contains an improved fix for the issue.","aliases":["GHSA-3fc8-2r3f-8wrg"],"modified":"2026-05-18T05:56:10.316344357Z","published":"2024-09-23T15:17:43.364Z","related":["GHSA-3fc8-2r3f-8wrg","GHSA-mxhq-xw3g-rphc"],"database_specific":{"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2024/47xxx/CVE-2024-47066.json","cwe_ids":["CWE-918"],"cna_assigner":"GitHub_M"},"references":[{"type":"WEB","url":"https://github.com/lobehub/lobe-chat/blob/main/src/app/api/proxy/route.ts"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2024/47xxx/CVE-2024-47066.json"},{"type":"ADVISORY","url":"https://github.com/lobehub/lobe-chat/security/advisories/GHSA-3fc8-2r3f-8wrg"},{"type":"ADVISORY","url":"https://github.com/lobehub/lobe-chat/security/advisories/GHSA-mxhq-xw3g-rphc"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2024-47066"},{"type":"FIX","url":"https://github.com/lobehub/lobe-chat/commit/e960a23b0c69a5762eb27d776d33dac443058faf"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/lobehub/lobehub","events":[{"introduced":"0"},{"fixed":"48a344f7c330a64d8ca71c601f6e533921beb726"}]}],"versions":["v1.19.12","v1.19.11","v1.19.10","v1.19.9","v1.19.8","v1.19.7","v1.19.6","v1.19.5","v1.19.4","v1.19.3","v1.19.2","v1.19.1","v1.19.0","v1.18.2","v1.18.1","v1.18.0","v1.17.7","v1.17.6","v1.17.5","v1.17.4","v1.17.3","v1.17.2","v1.17.1","v1.17.0","v1.16.14","v1.16.13","v1.16.12","v1.16.11","v1.16.10","v1.16.9","v1.16.8","v1.16.7","v1.16.6","v1.16.5","v1.16.4","v1.16.3","v1.16.2","v1.16.1","v1.16.0","v1.15.35","v1.15.34","v1.15.33","v1.15.32","v1.15.31","v1.15.30","v1.15.29","v1.15.28","v1.15.27","v1.15.26","v1.15.25","v1.15.24","v1.15.23","v1.15.22","v1.15.21","v1.15.20","v1.15.19","v1.15.18","v1.15.17","v1.15.16","v1.15.15","v1.15.14","v1.15.13","v1.15.12","v1.15.11","v1.15.10","v1.15.9","v1.15.8","v1.15.7","v1.15.6","v1.15.5","v1.15.4","v1.15.3","v1.15.2","v1.15.1","v1.15.0","v1.14.12","v1.14.11","v1.14.10","v1.14.9","v1.14.8","v1.14.7","v1.14.6","v1.14.5","v1.14.4","v1.14.3","v1.14.2","v1.14.1","v1.14.0","v1.13.2","v1.13.1","v1.13.0","v1.12.20","v1.12.19","v1.12.18","v1.12.17","v1.12.16","v1.12.15","v1.12.14","v1.12.13","v1.12.12","v1.12.11","v1.12.10","v1.12.9","v1.12.8","v1.12.7","v1.12.6","v1.12.5","v1.12.4","v1.12.3","v1.12.2","v1.12.1","v1.12.0","v1.11.9","v1.11.8","v1.11.7","v1.11.6","v1.11.5","v1.11.4","v1.11.3","v1.11.2","v1.11.1","v1.11.0","v1.10.1","v1.10.0","v1.9.8","v1.9.7","v1.9.6","v1.9.5","v1.9.4","v1.9.3","v1.9.2","v1.9.1","v1.9.0","v1.8.2","v1.8.1","v1.8.0","v1.7.10","v1.7.9","v1.7.8","v1.7.7","v1.7.6","v1.7.5","v1.7.4","v1.7.3","v1.7.2","v1.7.1","v1.7.0","v1.6.15","v1.6.14","v1.6.13","v1.6.12","v1.6.11","v1.6.10","v1.6.9","v1.6.8","v1.6.7","v1.6.6","v1.6.5","v1.6.4","v1.6.3","v1.6.2","v1.6.1","v1.6.0","v1.5.5","v1.5.4","v1.5.3","v1.5.2","v1.5.1","v1.5.0","v1.4.3","v1.4.2","v1.4.1","v1.4.0","v1.3.6","v1.3.5","v1.3.4","v1.3.3","v1.3.2","v1.3.1","v1.3.0","v1.2.14","v1.2.13","v1.2.12","v1.2.11","v1.2.10","v1.2.9","v1.2.8","v1.2.7","v1.2.6","v1.2.5","v1.2.4","v1.2.3","v1.2.2","v1.2.1","v1.2.0","v1.1.18","v1.1.17","v1.1.16","v1.1.15","v1.1.14","v1.1.13","v1.1.12","v1.1.11","v1.1.10","v1.1.9","v1.1.8","v1.1.7","v1.1.6","v1.1.5","v1.1.4","v1.1.3","v1.1.2","v1.1.1","v1.1.0","v1.0.14","v1.0.13","v1.0.12","v1.0.11","v1.0.10","v1.0.9","v1.0.8","v1.0.7","v1.0.6","v1.0.5","v1.0.4","v1.0.3","v1.0.2","v1.0.1","v0.162.25","v0.162.24","v0.162.23","v0.162.22","v0.162.21","v0.162.20","v0.162.19","v0.162.18","v0.162.17","v0.162.16","v0.162.15","v0.162.14","v0.162.13","v0.162.12","v0.162.11","v0.162.10","v0.162.9","v0.162.8","v0.162.7","v0.162.6","v0.162.5","v0.162.4","v0.162.3","v0.162.2","v0.162.1","v0.162.0","v0.161.25","v0.161.24","v0.161.23","v0.161.22","v0.161.21","v0.161.20","v0.161.19","v0.161.18","v0.161.17","v0.161.16","v0.161.15","v0.161.14","v0.161.13","v0.161.12","v0.161.11","v0.161.10","v0.161.9","v0.161.8","v0.161.7","v0.161.6","v0.161.5","v0.161.4","v0.161.3","v0.161.2","v0.161.1","v0.161.0","v0.160.8","v0.160.7","v0.160.6","v0.160.5","v0.160.4","v0.160.3","v0.160.2","v0.160.1","v0.160.0","v0.159.12","v0.159.11","v0.159.10","v0.159.9","v0.159.8","v0.159.7","v0.159.6","v0.159.5","v0.159.4","v0.159.3","v0.159.2","v0.159.1","v0.159.0","v0.158.2","v0.158.1","v0.158.0","v0.157.2","v0.157.1","v0.157.0","v0.156.2","v0.156.1","v0.156.0","v0.155.9","v0.155.8","v0.155.7","v0.155.6","v0.155.5","v0.155.4","v0.155.3","v0.155.2","v0.155.1","v0.155.0","v0.154.7","v0.154.6","v0.154.5","v0.154.4","v0.154.3","v0.154.2","v0.154.1","v0.154.0","v0.153.1","v0.153.0","v0.152.12","v0.152.11","v0.152.10","v0.152.9","v0.152.8","v0.152.7","v0.152.6","v0.152.5","v0.152.4","v0.152.3","v0.152.2","v0.152.1","v0.152.0","v0.151.11","v0.151.10","v0.151.9","v0.151.8","v0.151.7","v0.151.6","v0.151.5","v0.151.4","v0.151.3","v0.151.2","v0.151.1","v0.151.0","v0.150.10","v0.150.9","v0.150.8","v0.150.7","v0.150.6","v0.150.5","v0.150.4","v0.150.3","v0.150.2","v0.150.1","v0.150.0","v0.149.6","v0.149.5","v0.149.4","v0.149.3","v0.149.2","v0.149.1","v0.149.0","v0.148.10","v0.148.9","v0.148.8","v0.148.7","v0.148.6","v0.148.5","v0.148.4","v0.148.3","v0.148.2","v0.148.1","v0.148.0","v0.147.22","v0.147.21","v0.147.20","v0.147.19","v0.147.18","v0.147.17","v0.147.16","v0.147.15","v0.147.14","v0.147.13","v0.147.12","v0.147.11","v0.147.10","v0.147.9","v0.147.8","v0.147.7","v0.147.6","v0.147.5","v0.147.4","v0.147.3","v0.147.2","v0.147.1","v0.147.0","v0.146.2","v0.146.1","v0.146.0","v0.145.13","v0.145.12","v0.145.11","v0.145.10","v0.145.9","v0.145.8","v0.145.7","v0.145.6","v0.145.5","v0.145.4","v0.145.3","v0.145.2","v0.145.1","v0.145.0","v0.144.1","v0.144.0","v0.143.0","v0.142.9","v0.142.8","v0.142.7","v0.142.6","v0.142.5","v0.142.4","v0.142.3","v0.142.2","v0.142.1","v0.142.0","v0.141.2","v0.141.1","v0.141.0","v0.140.1","v0.140.0","v0.139.2","v0.139.1","v0.139.0","v0.138.2","v0.138.1","v0.138.0","v0.137.0","v0.136.0","v0.135.4","v0.135.3","v0.135.2","v0.135.1","v0.135.0","v0.134.1","v0.134.0","v0.133.5","v0.133.4","v0.133.3","v0.133.2","v0.133.1","v0.133.0","v0.132.2","v0.132.1","v0.132.0","v0.131.0","v0.130.7","v0.130.6","v0.130.5","v0.130.4","v0.130.3","v0.130.2","v0.130.1","v0.130.0","v0.129.6","v0.129.5","v0.129.4","v0.129.3","v0.129.2","v0.129.1","v0.129.0","v0.128.10","v0.128.9","v0.128.8","v0.128.7","v0.128.6","v0.128.5","v0.128.4","v0.128.3","v0.128.2","v0.128.1","v0.128.0","v0.127.2","v0.127.1","v0.127.0","v0.126.5","v0.126.4","v0.126.3","v0.126.2","v0.126.1","v0.126.0","v0.125.0","v0.124.3","v0.124.2","v0.124.1","v0.124.0","v0.123.4","v0.123.3","v0.123.2","v0.123.1","v0.123.0","v0.122.9","v0.122.8","v0.122.7","v0.122.6","v0.122.5","v0.122.4","v0.122.3","v0.122.2","v0.122.1","v0.122.0","v0.121.4","v0.121.3","v0.121.2","v0.121.1","v0.121.0","v0.120.6","v0.120.5","v0.120.4","v0.120.3","v0.120.2","v0.120.1","v0.120.0","v0.119.13","v0.119.12","v0.119.11","v0.119.10","v0.119.9","v0.119.8","v0.119.7","v0.119.6","v0.119.5","v0.119.4","v0.119.3","v0.119.2","v0.119.1","v0.119.0","v0.118.10","v0.118.9","v0.118.8","v0.118.7","v0.118.6","v0.118.5","v0.118.4","v0.118.3","v0.118.2","v0.118.1","v0.118.0","v0.117.5","v0.117.4","v0.117.3","v0.117.2","v0.117.1","v0.117.0","v0.116.5","v0.116.4","v0.116.3","v0.116.2","v0.116.1","v0.116.0","v0.115.13","v0.115.12","v0.115.11","v0.115.10","v0.115.9","v0.115.8","v0.115.7","v0.115.6","v0.115.5","v0.115.4","v0.115.3","v0.115.2","v0.115.1","v0.115.0","v0.114.9","v0.114.8","v0.114.7","v0.114.6","v0.114.5","v0.114.4","v0.114.3","v0.114.2","v0.114.1","v0.114.0","v0.113.1","v0.113.0","v0.112.1","v0.112.0","v0.111.6","v0.111.5","v0.111.4","v0.111.3","v0.111.2","v0.111.1","v0.111.0","v0.110.10","v0.110.9","v0.110.8","v0.110.7","v0.110.6","v0.110.5","v0.110.4","v0.110.3","v0.110.2","v0.110.1","v0.110.0","v0.109.1","v0.109.0","v0.108.0","v0.107.16","v0.107.15","v0.107.14","v0.107.13","v0.107.12","v0.107.11","v0.107.10","v0.107.9","v0.107.8","v0.107.7","v0.107.6","v0.107.5","v0.107.4","v0.107.3","v0.107.2","v0.107.1","v0.107.0","v0.106.0","v0.105.2","v0.105.1","v0.105.0","v0.104.0","v0.103.1","v0.103.0","v0.102.4","v0.102.3","v0.102.2","v0.102.1","v0.102.0","v0.101.7","v0.101.6","v0.101.5","v0.101.4","v0.101.3","v0.101.2","v0.101.1","v0.101.0","v0.100.5","v0.100.4","v0.100.3","v0.100.2","v0.100.1","v0.100.0","v0.99.1","v0.99.0","v0.98.3","v0.98.2","v0.98.1","v0.98.0","v0.97.1","v0.97.0","v0.96.9","v0.96.8","v0.96.7","v0.96.6","v0.96.5","v0.96.4","v0.96.3","v0.96.2","v0.96.1","v0.96.0","v0.95.1","v0.95.0","v0.94.5","v0.94.4","v0.94.3","v0.94.2","v0.94.1","v0.94.0","v0.93.0","v0.92.0","v0.91.0","v0.90.3","v0.90.2","v0.90.1","v0.90.0","v0.89.10","v0.89.9","v0.89.8","v0.89.7","v0.89.6","v0.89.5","v0.89.4","v0.89.3","v0.89.2","v0.89.1","v0.89.0","v0.88.0","v0.87.0","v0.86.5","v0.86.4","v0.86.3","v0.86.2","v0.86.1","v0.86.0","v0.85.3","v0.85.2","v0.85.1","v0.85.0","v0.84.0","v0.83.10","v0.83.9","v0.83.8","v0.83.7","v0.83.6","v0.83.5","v0.83.4","v0.83.3","v0.83.2","v0.83.1","v0.83.0","v0.82.9","v0.82.8","v0.82.7","v0.82.6","v0.82.5","v0.82.4","v0.82.3","v0.82.2","v0.82.1","v0.82.0","v0.80.2","v0.81.0","v0.80.1","v0.80.0","v0.79.8","v0.79.7","v0.79.6","v0.79.5","v0.79.4","v0.79.3","v0.79.2","v0.79.1","v0.79.0","v0.78.1","v0.78.0","v0.77.2","v0.77.1","v0.77.0","v0.76.2","v0.76.1","v0.76.0","v0.75.0","v0.74.0","v0.73.0","v0.72.4","v0.72.3","v0.72.2","v0.72.1","v0.72.0","v0.71.1","v0.71.0","v0.70.4","v0.70.3","v0.70.2","v0.70.1","v0.70.0","v0.69.1","v0.69.0","v0.68.1","v0.68.0","v0.67.0","v0.66.0","v0.65.1","v0.65.0","v0.64.1","v0.64.0","v0.63.3","v0.63.2","v0.63.1","v0.63.0","v0.62.1","v0.62.0","v0.61.0","v0.60.4","v0.60.3","v0.60.2","v0.60.1","v0.60.0","v0.59.0","v0.58.0","v0.57.0","v0.56.0","v0.55.1","v0.55.0","v0.54.4","v0.54.3","v0.54.2","v0.54.1","v0.54.0","v0.53.0","v0.52.1","v0.52.0","v0.51.0","v0.50.0","v0.49.0","v0.48.0","v0.47.0","v0.46.1","v0.46.0","v0.44.4","v0.44.3","v0.44.2","v0.44.1","v0.44.0","v0.43.0","v0.42.3","v0.42.2","v0.42.1","v0.42.0","v0.41.2","v0.41.1","v0.41.0","v0.40.7","v0.40.6","v0.40.5","v0.40.4","v0.40.3","v0.40.2","v0.40.1","v0.40.0","v0.39.3","v0.39.2","v0.39.1","v0.39.0","v0.38.0","v0.37.0","v0.36.1","v0.36.0","v0.35.1","v0.35.0","v0.33.0","v0.32.0","v0.31.0","v0.30.1","v0.30.0","v0.29.0","v0.28.0","v0.27.4","v0.27.3","v0.27.2","v0.27.1","v0.27.0","v0.26.1","v0.26.0","v0.25.0","v0.23.0","v0.22.2","v0.22.1","v0.22.0","v0.21.0","v0.20.0","v0.19.0","v0.18.2","v0.18.1","v0.18.0","v0.17.0","v0.16.1","v0.16.0","v0.15.1","v0.15.0","v0.14.0","v0.13.1","v0.13.0","v0.12.1","v0.12.0","v0.11.0","v0.10.2","v0.10.1","v0.10.0","v0.9.0","v0.8.2","v0.8.1","v0.8.0","v0.7.0","v0.6.1","v0.6.0","v0.5.0","v0.4.3","v0.4.2","v0.4.0","v0.3.0","v0.2.0","v0.1.5","v1.0.0"],"database_specific":{"source":"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2024-47066.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:L/A:H"}]}