PT-2025-39385 · Lobe Chat · Lobe Chat

Im-Soohyun

·

Published

2025-09-24

·

Updated

2025-09-25

·

CVE-2025-59426

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions Lobe Chat versions prior to 1.130.1
Description Lobe Chat, an open-source artificial intelligence chat framework, has an issue in its OIDC redirect handling logic. The logic builds the redirect URL’s host and protocol using the X-Forwarded-Host or Host headers and the X-Forwarded-Proto value. If a reverse proxy forwards client-supplied X-Forwarded-* headers without validation, or if the origin trusts them without validation, an attacker can inject an arbitrary host and trigger an open redirect to a malicious domain.
Recommendations Update to Lobe Chat version 1.130.1 or later.

Exploit

Fix

Open Redirect

Weakness Enumeration

Related Identifiers

CVE-2025-59426
GHSA-XPH5-278P-26QX

Affected Products

Lobe Chat