{"id":"CVE-2026-59095","title":"LobeChat before 2.2.10-canary.18 contains a server-side request forgery vulnerability that allows authenticated attackers to direct internal HTTP requests to arbitrary URLs by supplying user-controlled input to the skill import service (…","summary":"LobeChat before 2.2.10-canary.18 contains a server-side request forgery vulnerability that allows authenticated attackers to direct internal HTTP requests to arbitrary URLs by supplying user-controlled input to the skill import service (…","severity":"high","cvss":7.7,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N","cwe":["CWE-918"],"vendor":"lobehub","product":"lobehub","affected":["lobehub < 2.2.10"],"published":"2026-07-02","updated":"2026-09-30","sourceUpdated":"2026-09-30T18:18:37.990","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-59095","references":[{"url":"https://github.com/lobehub/lobehub/issues/16536","label":"disclosure@vulncheck.com"},{"url":"https://github.com/lobehub/lobehub/pull/16601","label":"disclosure@vulncheck.com"},{"url":"https://www.vulncheck.com/advisories/lobechat-canary-18-ssrf-via-importfromurl-and-fetchimagefromurl","label":"disclosure@vulncheck.com"}],"tags":["nvd","cve.org","exploit-available"],"epss":0.00402,"epssPercentile":0.31934,"exploitAvailable":true,"ssvc":{"exploitation":"poc","automatable":"no","technicalImpact":"partial","timestamp":"2026-07-06T19:00:31.444200Z"},"ingestedAt":"2026-09-30T18:17:24.557Z","slug":"CVE-2026-59095","body":"## Overview\n\nLobeChat before 2.2.10-canary.18 contains a server-side request forgery vulnerability that allows authenticated attackers to direct internal HTTP requests to arbitrary URLs by supplying user-controlled input to the skill import service (importFromUrl) and topic cover update (fetchImageFromUrl) endpoints, which use the global fetch without the project's ssrf-safe-fetch wrapper. Attackers can target internal addresses such as cloud instance metadata endpoints through these unprotected code paths to disclose internal service responses and cloud credentials.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"midnight","depthScore":54,"depthScoreParts":{"impact":42.4,"likelihood":0.1,"exploitation":12,"ransomware":0},"changes":[]}