<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Thu, 08 Oct 2026 14:54:56 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-290132</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-290132</link>
      <description>EUVD-2026-290132</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-290132</guid>
    </item>
    <item>
      <title>fkie_cve-2026-39411</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-39411</link>
      <description>&lt;p&gt;LobeHub is a work-and-lifestyle space to find, build, and collaborate with agent teammates that grow with you. Prior to 2.1.48, the webapi authentication layer trusts a client-controlled X-lobe-chat-auth header that is only XOR-obfuscated, not signed or otherwise authenticated. Because the XOR key is hardcoded in the repository, an attacker can forge arbitrary auth payloads and bypass authentication on protected webapi routes. Affected routes include /webapi/chat/[provider], /webapi/models/[provider], /webapi/models/[provider]/pull, and /webapi/create-image/comfyui. This vulnerability is fixed in 2.1.48.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;LobeHub is a work-and-lifestyle space to find, build, and collaborate with agent teammates that grow with you. Prior to 2.1.48, the webapi authentication layer trusts a client-controlled X-lobe-chat-auth header that is only XOR-obfuscated, not signed or otherwise authenticated. Because the XOR key is hardcoded in the repository, an attacker can forge arbitrary auth payloads and bypass authentication on protected webapi routes. Affected routes include /webapi/chat/[provider], /webapi/models/[provider], /webapi/models/[provider]/pull, and /webapi/create-image/comfyui. This vulnerability is fixed in 2.1.48.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-39411</guid>
    </item>
    <item>
      <title>GHSA-5mwj-v5jw-5c97 — LobeHub: Unauthenticated authentication bypass on `webapi` routes via forgeable `X-lobe-chat-auth` header</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-5mwj-v5jw-5c97</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: @lobehub/lobehub&lt;/p&gt;
&lt;p&gt;# Summary&lt;/p&gt;
&lt;p&gt;The `webapi` authentication layer trusts a client-controlled `X-lobe-chat-auth` header that is only XOR-obfuscated, not signed or otherwise authenticated. Because the XOR key is hardcoded in the repository, an attacker can forge arbitrary auth payloads and bypass authentication on protected `webapi` routes.&lt;/p&gt;
&lt;p&gt;Affected routes include:
- `POST /webapi/chat/[provider]`
- `GET /webapi/models/[provider]`
- `POST /webapi/models/[provider]/pull`
- `POST /webapi/create-image/comfyui`&lt;/p&gt;
&lt;p&gt;## Details&lt;/p&gt;
&lt;p&gt;The frontend creates `X-lobe-chat-auth` by XOR-obfuscating JSON with the static key `LobeHub · LobeHub`, and the backend reverses that operation and treats the decoded JSON as trusted authentication data.&lt;/p&gt;
&lt;p&gt;The backend then accepts any truthy `apiKey` field in that decoded payload as sufficient authentication. No real API key validation is performed in this path.&lt;/p&gt;
&lt;p&gt;As a result, an unauthenticated attacker can forge payloads such as:&lt;/p&gt;
&lt;p&gt;```json
{&amp;#34;apiKey&amp;#34;:&amp;#34;x&amp;#34;} 
```&lt;/p&gt;
&lt;p&gt;or&lt;/p&gt;
&lt;p&gt;``` {&amp;#34;userId&amp;#34;:&amp;#34;victim-user-123&amp;#34;,&amp;#34;apiKey&amp;#34;:&amp;#34;x&amp;#34;} ```&lt;/p&gt;
&lt;p&gt;and access webapi routes as an authenticated user.&lt;/p&gt;
&lt;p&gt;Confirmed PoC
The following forged header was generated directly from the published XOR key using payload {&amp;#34;apiKey&amp;#34;:&amp;#34;x&amp;#34;}:&lt;/p&gt;
&lt;p&gt;``` X-lobe-chat-auth: N00DFSE+B1ngjQI0TR8= ```&lt;/p&gt;
&lt;p&gt;That header decodes server-side to:&lt;/p&gt;
&lt;p&gt;``` {&amp;#34;apiKey&amp;#34;:&amp;#34;x&amp;#34;}```&lt;/p&gt;
&lt;p&gt;A simple request is:&lt;/p&gt;
&lt;p&gt;``` curl &amp;#39;https://TARGET/webapi/models/openai&amp;#39; \
  -H &amp;#39;X-lobe-chat-auth: N00DFSE+B1ngjQI0TR8=&amp;#39; ```&lt;/p&gt;
&lt;p&gt;If the deployment has OPENAI_API_KEY configured, the request should…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: @lobehub/lobehub&lt;/p&gt;
&lt;p&gt;# Summary&lt;/p&gt;
&lt;p&gt;The `webapi` authentication layer trusts a client-controlled `X-lobe-chat-auth` header that is only XOR-obfuscated, not signed or otherwise authenticated. Because the XOR key is hardcoded in the repository, an attacker can forge arbitrary auth payloads and bypass authentication on protected `webapi` routes.&lt;/p&gt;
&lt;p&gt;Affected routes include:
- `POST /webapi/chat/[provider]`
- `GET /webapi/models/[provider]`
- `POST /webapi/models/[provider]/pull`
- `POST /webapi/create-image/comfyui`&lt;/p&gt;
&lt;p&gt;## Details&lt;/p&gt;
&lt;p&gt;The frontend creates `X-lobe-chat-auth` by XOR-obfuscating JSON with the static key `LobeHub · LobeHub`, and the backend reverses that operation and treats the decoded JSON as trusted authentication data.&lt;/p&gt;
&lt;p&gt;The backend then accepts any truthy `apiKey` field in that decoded payload as sufficient authentication. No real API key validation is performed in this path.&lt;/p&gt;
&lt;p&gt;As a result, an unauthenticated attacker can forge payloads such as:&lt;/p&gt;
&lt;p&gt;```json
{&amp;#34;apiKey&amp;#34;:&amp;#34;x&amp;#34;} 
```&lt;/p&gt;
&lt;p&gt;or&lt;/p&gt;
&lt;p&gt;``` {&amp;#34;userId&amp;#34;:&amp;#34;victim-user-123&amp;#34;,&amp;#34;apiKey&amp;#34;:&amp;#34;x&amp;#34;} ```&lt;/p&gt;
&lt;p&gt;and access webapi routes as an authenticated user.&lt;/p&gt;
&lt;p&gt;Confirmed PoC
The following forged header was generated directly from the published XOR key using payload {&amp;#34;apiKey&amp;#34;:&amp;#34;x&amp;#34;}:&lt;/p&gt;
&lt;p&gt;``` X-lobe-chat-auth: N00DFSE+B1ngjQI0TR8= ```&lt;/p&gt;
&lt;p&gt;That header decodes server-side to:&lt;/p&gt;
&lt;p&gt;``` {&amp;#34;apiKey&amp;#34;:&amp;#34;x&amp;#34;}```&lt;/p&gt;
&lt;p&gt;A simple request is:&lt;/p&gt;
&lt;p&gt;``` curl &amp;#39;https://TARGET/webapi/models/openai&amp;#39; \
  -H &amp;#39;X-lobe-chat-auth: N00DFSE+B1ngjQI0TR8=&amp;#39; ```&lt;/p&gt;
&lt;p&gt;If the deployment has OPENAI_API_KEY configured, the request should…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-5mwj-v5jw-5c97</guid>
    </item>
  </channel>
</rss>
