S4E just found a high top 10 tcp port service scan
critical·Product Based Web Vulnerabilities·Updated Oct 8, 2024

CVE-2024-32964 Scanner

CVE-2024-32964 Scanner - Server-Side Request Forgery (SSRF) vulnerability in Lobe Chat

Est. Time~1 minutes
Scan TypeSingle Scan
Targetsdomain, ipv4, subdomain
CostFree
2.8k
Times Used
continuous scan runs
3.4k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2024-32964
9.0
CVSScritical
Exploitable remotely over the internet · requires high privileges.

Lobe Chat is a chatbot framework that supports speech synthesis, multimodal, and extensible Function Call plugin system. Prior to 0.150.6, lobe-chat had an unauthorized Server-Side Request Forgery vulnerability in the /api/proxy endpoint. An attacker can construct malicious requests to cause Server-Side Request Forgery without logging in, attack intranet services, and leak sensitive information.

Attack Vector
Network
Privileges Req.
High
User Interaction
None
Affected
lobe-chatby lobehub
<= 0.150.5
lobe_chatby lobehub
AFFECTED< 0.150.6SAFE ✓≥ 0.150.6
Updated Aug 22, 2026View on NVD →
Detail

Lobe Chat is an innovative chatbot framework used widely in conversational AI and human-computer interaction fields. It provides support for speech synthesis, multimodal interactions, and a highly extensible Function Call plugin system, allowing developers to tailor its functionalities according to their needs. The chatbot is commonly deployed in sectors needing advanced customer support, including tech support and banking automation systems. Its flexibility and robust plugin architecture allow seamless integration with existing platforms and enhance user interaction experiences. The software is utilized by developers, businesses, and researchers aiming to leverage AI to improve communication interfaces. Due to its adaptability and ease of use, Lobe Chat continues to gain popularity across various industries and sectors requiring sophisticated interactive applications.

A Server-Side Request Forgery (SSRF) vulnerability allows an attacker to make unauthorized requests from a server to unintended destinations, potentially leading to data compromise. The SSRF vulnerability may be exploited by crafting requests that the server cannot distinguish from legitimate ones, allowing access to internal resources. Attackers can leverage SSRF to conduct various attacks, such as accessing internal control panels, exploiting further network flaws, or leaking sensitive internal data. This vulnerability's presence in a networked application poses significant security risks. Thus, identifying it promptly is critical to safeguard against unintended data exposure or compromise. The severity of SSRF lies in its potential to pivot attacks deeper into a network.

The vulnerability in Lobe Chat was identified in the /api/proxy endpoint, which could be manipulated by an attacker for malicious purposes. By crafting specific POST requests to this endpoint, an attacker could coerce the server into revealing internal network details or reach internal services. The flaw arises from inadequate input validation, allowing crafted requests to bypass access controls and interact with internal services. The exploitation involves using basic HTTP methods without authentication, which may lead to extensive data leaks or system manipulation. This vulnerability underscores the importance of secure coding practices and thorough validation checks.

When exploited, this vulnerability could allow attackers unauthorized access to internal services, potentially compromising sensitive data. An attacker might use it to scan the internal network, access restricted interfaces, or extract confidential information. The exploitation of this vulnerability could serve as a stepping stone to broader attacks against the affected infrastructure. Due to the potential for data breaches and increased legal liabilities, this vulnerability poses a critical security threat. Additionally, SSRF can disrupt normal service operations, resulting in downtime or degraded service quality.

REFERENCES

Solution Advice
  • Update Lobe Chat to the latest version where the vulnerability has been patched.
  • Implement strict input validation to mitigate unauthorized proxy requests.
  • Employ network segmentation to limit server communication to only necessary endpoints.
  • Use a web application firewall (WAF) to detect and block exploitative SSRF patterns.
  • Conduct regular security audits to identify and rectify vulnerabilities before they can be exploited.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.

CVE-2024-32964 Scanner - Server-Side Request Forgery (SSRF) vulnerability in Lobe Chat S4E