MEDIUM5.0npm
GHSA-5mwj-v5jw-5c97· CVE-2026-39411LobeHub: Unauthenticated authentication bypass on `webapi` routes via forgeable `X-lobe-chat-auth` header
Modified: 4/9/2026
package
pkg:npm/%40lobehub/lobehub
LobeHub: Unauthenticated authentication bypass on `webapi` routes via forgeable `X-lobe-chat-auth` header
Modified: 4/9/2026
LobeHub: Unauthenticated SSRF in `/webapi/proxy`
Modified: 7/20/2026
LobeHub has a Cross-Site Scripting issue that escalates to Remote Code Execution
Modified: 5/13/2026