PT-2026-3454 · Lobe Chat · Lobe Chat
Denizparlak
·
Published
2026-01-19
·
Updated
2026-01-20
·
CVE-2026-23522
CVSS v3.1
3.7
Low
| Vector | AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
LobeChat versions prior to 2.0.0-next.193
Description
LobeChat is an open source chat application platform. Prior to version 2.0.0-next.193, the
knowledgeBase.removeFilesFromKnowledgeBase tRPC endpoint allows authenticated users to delete files from any knowledge base without proper ownership verification. The userId filter in the database query is commented out, enabling attackers to delete other users' knowledge base files if they know the knowledge base ID and file ID. Practical exploitation requires knowing the target's knowledge base ID and file ID, which may leak through shared links, logs, or referrer headers. This missing authorization check is a critical security flaw.Recommendations
Upgrade to version 2.0.0-next.193 to receive a patch.
Exploit
Fix
Missing Authorization
Improper Access Control
IDOR
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Lobe Chat