Lobe Chat API Key Leak
Moderate severity
GitHub Reviewed
Published
Jun 17, 2024
in
lobehub/lobe-chat
•
Updated Jun 17, 2024
Description
Published by the National Vulnerability Database
Jun 17, 2024
Published to the GitHub Advisory Database
Jun 17, 2024
Reviewed
Jun 17, 2024
Last updated
Jun 17, 2024
Summary
If an attacker can successfully authenticate through SSO/Access Code, they can obtain the real backend API Key by modifying the base URL to their own attack URL on the frontend and setting up a server-side request.
Details
The attack process is described above.
PoC
Frontend:
Backend:
Impact
All community version LobeChat users using SSO/Access Code authentication, tested on version 0.162.13.
References