# CVE-2026-54157: LobeHub - SSRF

> Live exploitation tracking for CVE-2026-54157 by the CrowdSec Live Exploit Tracker, built from real-world attack data crowdsourced from CrowdSec's global network.

Page: https://tracker.crowdsec.net/cves/CVE-2026-54157

## Key facts

- **Exploitation phase:** Limited Exploitation. The vulnerability is known but shows very limited attacker interest or exploitation activity.
- **CVSS score:** 9.0
- **Public exploit available:** Yes
- **Affected products:** LobeHub
- **Weaknesses:** CWE-918 (Server-Side Request Forgery (SSRF))
- **Tags:** web_application

## Description

LobeHub is a work-and-lifestyle space to find, build, and collaborate with agent teammates that grow with you. Prior to 2.1.57, the /webapi/proxy endpoint on app.lobehub.com accepts a URL in the POST body and fetches it server-side without any authentication. An attacker can use this to make arbitrary outbound requests from LobeHub's infrastructure, leak Vercel deployment details, and inject cookies on the LobeHub.com domain through reflected Set-Cookie headers. This vulnerability is fixed in 2.1.57.

## CrowdSec analysis

[CVE-2026-54157](https://euvd.enisa.europa.eu/vulnerability/CVE-2026-54157) is a critical server-side request forgery (SSRF) vulnerability in LobeHub prior to version 2.1.57, where the /webapi/proxy endpoint allows unauthenticated attackers to make arbitrary outbound requests from the application's infrastructure. Exploiting this flaw could enable attackers to leak sensitive Vercel deployment information and inject malicious cookies into the LobeHub.com domain, potentially leading to further compromise or session hijacking.

CrowdSec has been tracking this vulnerability and its exploits since 24th of June 2026.

CrowdSec has not observed any significant exploitation activity targeting CVE-2026-54157 across its network. As a result, no community-driven trend analysis is available for this vulnerability at this time.

Attackers exploit the `/webapi/proxy` endpoint by sending unauthenticated POST requests containing arbitrary URLs, causing the server to make outbound HTTP requests on their behalf. This enables server-side request forgery (SSRF) against LobeHub LobeChat instances up to version 2.1.56.

## Timeline

- 2026-06-23: CVE Published. CVE-2026-54157 is published to NVD.
- 2026-06-24: Rule Released. CrowdSec releases a rule to detect CVE-2026-54157 exploitation attempts against the CrowdSec Network.
- 2026-07-15: CrowdSec First Seen. CrowdSec observes in-the-wild exploitation of CVE-2026-54157 for the first time.

## References

- https://github.com/lobehub/lobehub/security/advisories/GHSA-xmwj-c75x-6346
- https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2026/CVE-2026-54157.yaml

## Live exploitation data

The [Live Exploit Tracker page](https://tracker.crowdsec.net/cves/CVE-2026-54157) follows observed exploitation activity for CVE-2026-54157. [Request an API key](https://tracker.crowdsec.net/request-api-key) for full access to its exploitation timeline, attacking IP addresses and blocklists.
