CVE-2025-59426

⚪ Do wiadomości

Otwarte przekierowanie w Lobe Chat umożliwia atakującemu wysłanie użytkowników na złośliwą stronę.

CVSS
4.3
EPSS
0.3%
Exploit
poc
Vendor
lobehub
Opis źródłowy (NVD)

Lobe Chat is an open-source artificial intelligence chat framework. Prior to version 1.130.1, the project's OIDC redirect handling logic constructs the host and protocol of the final redirect URL based on the X-Forwarded-Host or Host headers and the X-Forwarded-Proto value. In deployments where a reverse proxy forwards client-supplied X-Forwarded-* headers to the origin as-is, or where the origin trusts them without validation, an attacker can inject an arbitrary host and trigger an open redirect that sends users to a malicious domain. This issue has been patched in version 1.130.1.

exploit Brak patcha
Źródła i daty
ŹródłoWartość
NVD – CVSS4.3
CISA KEV (aktywnie wykorzystywane)Nie
FIRST EPSS (prawdopodobieństwo exploita)0.3%
Opublikowano (NVD)2025-09-25 14:15:45 UTC
Ostatnia modyfikacja (NVD)2026-09-30 23:10:00 UTC
Referencje