Sploitus

CVE-2026-59095

No indexed exploits for CVE-2026-59095 yet

LobeChat before 2.2.10-canary.18 contains a server-side request forgery vulnerability that allows authenticated attackers to direct internal HTTP requests to arbitrary URLs by supplying user-controlled input to the skill import service (importFromUrl) and topic cover update (fetchImageFromUrl) endpoints, which use the global fetch without the project's ssrf-safe-fetch wrapper. Attackers can target internal addresses such as cloud instance metadata endpoints through these unprotected code paths to disclose internal service responses and cloud credentials.

Affected products
Lobe Chat
Fix
Available
CVSS 4.0
8.3 HIGH
CVSS 3.1
7.7 HIGH
EPSS
0.2% (15th percentile)
Weakness
CWE-918
NVD status
Deferred
Published
2026-07-02
CVE-2026-59095 at NVD
Authoritative description, scoring and affected products

No indexed exploits for CVE-2026-59095 yet

Our index is partial: it proves presence, never absence

No exploit for CVE-2026-59095 has been indexed yet. Our index is built from live traffic and upstream syncs, so this page can only say what it knows — not that no exploit exists.