CrowdSecLive Exploit Tracker
Limited ExploitationCVE-2026-54157Public Exploit

LobeHub - SSRF (CVE-2026-54157)

PublishedJun 23, 2026
First SeenJul 15, 2026
Last Seen
Reported
CVSS9.0
web_application

Description

LobeHub is a work-and-lifestyle space to find, build, and collaborate with agent teammates that grow with you. Prior to 2.1.57, the /webapi/proxy endpoint on app.lobehub.com accepts a URL in the POST body and fetches it server-side without any authentication. An attacker can use this to make arbitrary outbound requests from LobeHub's infrastructure, leak Vercel deployment details, and inject cookies on the LobeHub.com domain through reflected Set-Cookie headers. This vulnerability is fixed in 2.1.57.

psychologyCrowdSec Analysis

CVE-2026-54157 is a critical server-side request forgery (SSRF) vulnerability in LobeHub prior to version 2.1.57, where the /webapi/proxy endpoint allows unauthenticated attackers to make arbitrary outbound requests from the application's infrastructure. Exploiting this flaw could enable attackers to leak sensitive Vercel deployment information and inject malicious cookies into the LobeHub.com domain, potentially leading to further compromise or session hijacking.

CrowdSec has been tracking this vulnerability and its exploits since 24th of June 2026.

CrowdSec has not observed any significant exploitation activity targeting CVE-2026-54157 across its network. As a result, no community-driven trend analysis is available for this vulnerability at this time.

Attackers exploit the /webapi/proxy endpoint by sending unauthenticated POST requests containing arbitrary URLs, causing the server to make outbound HTTP requests on their behalf. This enables server-side request forgery (SSRF) against LobeHub LobeChat instances up to version 2.1.56.

lock

Full Intelligence Available

Connect your API key to access CrowdSec scores, exploit timelines, and attacker IPs.

EventDate
CVE Published2026-06-23
Rule Released2026-06-24
CrowdSec First Seen2026-07-15

Remediation & Protection

lock to download blocklists, subscribe to firewalls, and access IP intelligence.