CVE-2024-47066
JavaScript vulnerability analysis and mitigation

Overview

Lobe Chat, an open-source artificial intelligence chat framework, was found to have a Server-Side Request Forgery (SSRF) vulnerability in versions prior to 1.19.13. The vulnerability was identified in the server-side request forgery protection implemented in src/app/api/proxy/route.ts (NVD, GitHub Advisory).

Technical details

The vulnerability stems from insufficient SSRF protection that does not properly handle URL redirects. The protection mechanism could be bypassed when an attacker provides an external malicious URL that redirects to internal resources such as private networks or loopback addresses. The vulnerability has been assigned a CVSS v3.1 base score of 8.8 (HIGH) by NVD and 9.0 (CRITICAL) by GitHub, indicating its severe nature (NVD).

Impact

If exploited, this vulnerability could allow attackers to perform SSRF attacks against internal network resources, potentially leading to unauthorized access to private networks and sensitive information disclosure. The vulnerability enables attackers to bypass security controls and access internal services that should not be accessible from external networks (GitHub Advisory).

Exploitability

The vulnerability can be exploited without user interaction and requires only network access. A proof of concept has been demonstrated showing how an attacker can bypass the SSRF protection by using a malicious URL that redirects to internal resources. The exploit has been confirmed to work in containerized environments (GitHub Advisory).

Mitigation and workarounds

The vulnerability has been fixed in version 1.19.13 of Lobe Chat. The recommended mitigation is to upgrade to this version or later. For those unable to upgrade immediately, it is recommended to disable redirects or implement additional checks before each HTTP request to prevent SSRF attacks (GitHub Advisory).

Additional resources


SourceThis report was generated using AI

Related JavaScript vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-77415CRITICAL9.3
  • JavaScript logoJavaScript
  • jsonata
NoYesAug 21, 2026
CVE-2026-77414CRITICAL9.3
  • JavaScript logoJavaScript
  • jsonata
NoYesAug 21, 2026
CVE-2026-77413CRITICAL9.3
  • JavaScript logoJavaScript
  • jsonata
NoYesAug 21, 2026
CVE-2026-63421HIGH7.5
  • JavaScript logoJavaScript
  • @keystone-6/core
NoYesAug 21, 2026
CVE-2026-53509MEDIUM5.7
  • JavaScript logoJavaScript
  • @aborruso/ckan-mcp-server
NoYesAug 21, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management