<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-10T12:36:28.721107+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-329673</id>
    <title>EUVD-2026-329673</title>
    <updated>2026-10-10T12:36:28.723363+00:00</updated>
    <content>EUVD-2026-329673</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-329673"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-54157</id>
    <title>fkie_cve-2026-54157</title>
    <updated>2026-10-10T12:36:28.723394+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>LobeHub is a work-and-lifestyle space to find, build, and collaborate with agent teammates that grow with you. Prior to 2.1.57, the /webapi/proxy endpoint on app.lobehub.com accepts a URL in the POST body and fetches it server-side without any authentication. An attacker can use this to make arbitrary outbound requests from LobeHub's infrastructure, leak Vercel deployment details, and inject cookies on the lobehub.com domain through reflected Set-Cookie headers. This vulnerability is fixed in 2.1.57.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-54157"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-xmwj-c75x-6346</id>
    <title>GHSA-xmwj-c75x-6346 — LobeHub: Unauthenticated SSRF in `/webapi/proxy`</title>
    <updated>2026-10-10T12:36:28.723428+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> npm: @lobehub/lobehub</p>
<p>## Unauthenticated SSRF in /webapi/proxy allows anyone to proxy requests and inject cookies on lobehub.com</p>
<p>## Summary</p>
<p>The `/webapi/proxy` endpoint on app.lobehub.com accepts a URL in the POST body and fetches it server-side without any authentication. This is the same proxy code that was vulnerable in CVE-2024-32964, where `/api/proxy` was fixed by adding auth middleware. The `/webapi/proxy` route was never secured — it is the only webapi route missing the `checkAuth()` wrapper. An attacker can use this to make arbitrary outbound requests from LobeHub's infrastructure, leak Vercel deployment details, and inject cookies on the `lobehub.com` domain through reflected `Set-Cookie` headers.</p>
<p>## Vulnerability Details</p>
<p>**Type:** Server-Side Request Forgery (CWE-918)
**Affected Endpoint:** POST /webapi/proxy
**Vulnerable File:** `src/app/(backend)/webapi/proxy/route.ts`</p>
<p>The route handler reads a URL from the request body and passes it to `ssrfSafeFetch()` without calling `checkAuth()` first. Every other webapi route (`/webapi/chat/*`, `/webapi/models/*`, `/webapi/create-image/*`) wraps the handler in `checkAuth()`, but the proxy does not. The Next.js middleware also skips `/webapi/` routes — `defaultMiddleware()` calls `NextResponse.next()` for any path starting with `/webapi/`, so neither the route handler nor the middleware performs authentication.</p>
<p>## Steps to Reproduce</p>
<p>**Fetch an external URL through the proxy (no auth, no cookies, no tokens):**</p>
<p>```
curl -X POST -H "Content…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-xmwj-c75x-6346"/>
  </entry>
</feed>
