LobeHub - SSRF (CVE-2026-54157)
Description
LobeHub is a work-and-lifestyle space to find, build, and collaborate with agent teammates that grow with you. Prior to 2.1.57, the /webapi/proxy endpoint on app.lobehub.com accepts a URL in the POST body and fetches it server-side without any authentication. An attacker can use this to make arbitrary outbound requests from LobeHub's infrastructure, leak Vercel deployment details, and inject cookies on the LobeHub.com domain through reflected Set-Cookie headers. This vulnerability is fixed in 2.1.57.
psychologyCrowdSec Analysis
CVE-2026-54157 is a critical server-side request forgery (SSRF) vulnerability in LobeHub prior to version 2.1.57, where the /webapi/proxy endpoint allows unauthenticated attackers to make arbitrary outbound requests from the application's infrastructure. Exploiting this flaw could enable attackers to leak sensitive Vercel deployment information and inject malicious cookies into the LobeHub.com domain, potentially leading to further compromise or session hijacking.
CrowdSec has been tracking this vulnerability and its exploits since 24th of June 2026.
CrowdSec has not observed any significant exploitation activity targeting CVE-2026-54157 across its network. As a result, no community-driven trend analysis is available for this vulnerability at this time.
Attackers exploit the /webapi/proxy endpoint by sending unauthenticated POST requests containing arbitrary URLs, causing the server to make outbound HTTP requests on their behalf. This enables server-side request forgery (SSRF) against LobeHub LobeChat instances up to version 2.1.56.
Full Intelligence Available
Connect your API key to access CrowdSec scores, exploit timelines, and attacker IPs.
| Event | Date |
|---|---|
| CVE Published | 2026-06-23 |
| Rule Released | 2026-06-24 |
| CrowdSec First Seen | 2026-07-15 |