CVE-2024-47066
JavaScript vulnerability analysis and mitigation

Overview

Lobe Chat, an open-source artificial intelligence chat framework, was found to have a Server-Side Request Forgery (SSRF) vulnerability in versions prior to 1.19.13. The vulnerability was identified in the server-side request forgery protection implemented in src/app/api/proxy/route.ts (NVD, GitHub Advisory).

Technical details

The vulnerability stems from insufficient SSRF protection that does not properly handle URL redirects. The protection mechanism could be bypassed when an attacker provides an external malicious URL that redirects to internal resources such as private networks or loopback addresses. The vulnerability has been assigned a CVSS v3.1 base score of 8.8 (HIGH) by NVD and 9.0 (CRITICAL) by GitHub, indicating its severe nature (NVD).

Impact

If exploited, this vulnerability could allow attackers to perform SSRF attacks against internal network resources, potentially leading to unauthorized access to private networks and sensitive information disclosure. The vulnerability enables attackers to bypass security controls and access internal services that should not be accessible from external networks (GitHub Advisory).

Mitigation and workarounds

The vulnerability has been fixed in version 1.19.13 of Lobe Chat. The recommended mitigation is to upgrade to this version or later. For those unable to upgrade immediately, it is recommended to disable redirects or implement additional checks before each HTTP request to prevent SSRF attacks (GitHub Advisory).

Additional resources


SourceThis report was generated using AI

Related JavaScript vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2025-65959HIGH8.7
  • JavaScriptJavaScript
  • open-webui
NoYesDec 04, 2025
CVE-2025-66032HIGH8.7
  • JavaScriptJavaScript
  • @anthropic-ai/claude-code
NoYesDec 03, 2025
CVE-2025-65945HIGH7.5
  • JavaScriptJavaScript
  • jws
NoYesDec 04, 2025
CVE-2025-66404MEDIUM6.4
  • JavaScriptJavaScript
  • mcp-server-kubernetes
NoYesDec 03, 2025
CVE-2025-66479LOW1.8
  • JavaScriptJavaScript
  • @anthropic-ai/sandbox-runtime
NoYesDec 04, 2025

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management