VDB
Sign up
MEDIUM5.7

GHSA-p36r-qxgx-jq2v

Lobe Chat API Key Leak

Quick fix

GHSA-p36r-qxgx-jq2v — @lobehub/chat: upgrade to the fixed version with the command below.

npm install @lobehub/chat@0.162.25

Details

### Summary

If an attacker can successfully authenticate through SSO/Access Code, they can obtain the real backend API Key by modifying the base URL to their own attack URL on the frontend and setting up a server-side request.

### Details

The attack process is described above.

![image](https://github.com/lobehub/lobe-chat/assets/36695271/df5e0c3c-af28-45c3-959f-182cc9d06680)

### PoC

Frontend: 1. Pass basic authentication (SSO/Access Code). 2. Set the Base URL to a private attack address. 3. Configure the request method to be a server-side request. 4. At the self-set attack address, retrieve the API Key information from the request headers.

Backend: 1. The LobeChat version allows setting the Base URL. 2. There is no outbound traffic whitelist.

### Impact

All community version LobeChat users using SSO/Access Code authentication, tested on version 0.162.13.

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/@lobehub/chat
Introduced in: 0Fixed in: 0.162.25
Fixnpm install @lobehub/chat@0.162.25

References