GHSA-p36r-qxgx-jq2v
Lobe Chat API Key Leak
Quick fix
GHSA-p36r-qxgx-jq2v — @lobehub/chat: upgrade to the fixed version with the command below.
npm install @lobehub/chat@0.162.25Details
### Summary
If an attacker can successfully authenticate through SSO/Access Code, they can obtain the real backend API Key by modifying the base URL to their own attack URL on the frontend and setting up a server-side request.
### Details
The attack process is described above.

### PoC
Frontend: 1. Pass basic authentication (SSO/Access Code). 2. Set the Base URL to a private attack address. 3. Configure the request method to be a server-side request. 4. At the self-set attack address, retrieve the API Key information from the request headers.
Backend: 1. The LobeChat version allows setting the Base URL. 2. There is no outbound traffic whitelist.
### Impact
All community version LobeChat users using SSO/Access Code authentication, tested on version 0.162.13.
Are you affected?
Enter the version of the package you're using.