Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2528▼ 418 respecto a la semana anterior
Críticas / altas1311▲ 21 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)99▼ 428 respecto a la semana anterior
10 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (6.9) | 0.20% | — | Lobehub LobechatAI | 4/9/2026 | 24/9/2026 | LobeChat (LobeHub) 2.2.1 does not properly verify inbound chat-platform webhook signatures in the QQ and Feishu adapters. The webhook route (/api/agent/webhooks/:platform) is unauthenticated by design and delegates verification to each adapter; the QQ adapter performs no Ed25519 signature verification on dispatched… | |
| Aplazada | Baja (2.3) | 0.29% | — | LobechatAI | 2/7/2026 | 14/7/2026 | LobeChat through 2.2.9 contains a broken object level authorization vulnerability that allows authenticated attackers to access and modify other users' chat-group agent data by supplying arbitrary group identifiers. Attackers can invoke the getGroupAgents, updateAgentInGroup, and removeAgentsFromGroup operations… | |
| Aplazada | Alta (7.1) | 0.41% | — | LobechatAI | 2/7/2026 | 14/7/2026 | LobeChat through 2.2.9 contains a broken access control vulnerability in the retrieval-augmented-generation semantic search functionality that allows authenticated attackers to access other users' data by exploiting missing user-identifier predicates in the chunk model semanticSearch method. Attackers can supply… | |
| Aplazada | Media (6) | 0.25% | — | LobechatAI | 2/7/2026 | 14/7/2026 | LobeChat through 2.2.9 server-database deployments are vulnerable to broken object-level authorization in MessageModel. The updateMessagePlugin, updatePluginState, updatePluginError, updateTTS and updateTranslate methods filter target rows by message id alone, omitting the userId scope that sibling methods apply, and… | |
| Aplazada | Alta (7.1) | 0.55% | — | LobechatAI | 2/7/2026 | 14/7/2026 | LobeChat before version 2.2.10-canary.15 contains a regular expression denial of service (ReDoS) vulnerability that allows authenticated attackers to block the Node.js event loop by supplying a catastrophic-backtracking pattern in a GitHub repository URL path during skill import. Attackers can craft a malicious… | |
| Aplazada | Alta (8.3) | 0.40% | — | LobechatAI | 2/7/2026 | 30/9/2026 | LobeChat before 2.2.10-canary.18 contains a server-side request forgery vulnerability that allows authenticated attackers to direct internal HTTP requests to arbitrary URLs by supplying user-controlled input to the skill import service (importFromUrl) and topic cover update (fetchImageFromUrl) endpoints, which use the… | |
| Aplazada | Media (6.2) | 0.35% | — | Lobehub LobechatAI | 12/5/2026 | 17/6/2026 | LobeHub is a work-and-lifestyle space to find, build, and collaborate with agent teammates that grow with you. Prior to 2.1.48, when LobeChat processes custom tags in the Render process of src/features/Portal/Artifacts/Body/Renderer/index.tsx, if no type match is found, it will choose to call the default method,… | |
| Aplazada | Baja (3.7) | 0.23% | — | LobechatAI | 19/1/2026 | 17/6/2026 | LobeChat is an open source chat application platform. Prior to version 2.0.0-next.193, `knowledgeBase.removeFilesFromKnowledgeBase` tRPC ep allows authenticated users to delete files from any knowledge base without verifying ownership. `userId` filter in the database query is commented out, so it's enabling attackers… | |
| Aplazada | Media (6.4) | 0.14% | — | LobechatAI | 18/1/2026 | 17/6/2026 | LobeChat is an open source chat application platform. Prior to version 2.0.0-next.180, a stored Cross-Site Scripting (XSS) vulnerability in the Mermaid artifact renderer allows attackers to execute arbitrary JavaScript within the application context. This XSS can be escalated to Remote Code Execution (RCE) by… | |
| Aplazada | Baja (3) | 0.32% | — | LobechatAI | 17/10/2025 | 17/6/2026 | LobeChat is an open source chat application platform. The web-crawler package in LobeChat version 1.136.1 allows server-side request forgery (SSRF) in the tools.search.crawlPages tRPC endpoint. A client can supply an arbitrary urls array together with impls containing the value naive. The service passes the user URLs… |