PT-2024-25012 · Openai · Openai Api

·

CVE-2024-32965

·

Published

2024-11-26

·

Updated

2025-09-23

CVSS v3.1

8.6

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:L
Name of the Vulnerable Software and Affected Versions lobe-chat versions prior to 1.19.13
Description Lobe Chat is an open-source, AI chat framework. The issue allows an attacker to construct malicious requests to cause SSRF without logging in, attack intranet services, and leak sensitive information. The jwt token header X-Lobe-Chat-Auth stored proxy address and OpenAI API Key can be modified to scan an internal network in the target lobe-web environment.
Recommendations For versions prior to 1.19.13, upgrade to version 1.19.13 or later to resolve the issue. As a temporary workaround, consider restricting access to the X-Lobe-Chat-Auth header and the OpenAI API Key to minimize the risk of exploitation. Avoid using the X-Lobe-Chat-Auth header and the OpenAI API Key in the affected API endpoint until the issue is resolved.

Exploit

Fix

SSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2024-32965
GHSA-2XCC-VM3F-M8RW

Affected Products

Openai Api