FixVibe

critical

LobeHub Unauthenticated SSRF in /webapi/proxy (CVE-2026-54157)

LobeHub versions through 2.1.56 expose an unauthenticated server-side proxy route. FixVibe verified active scans flag deployments where that route fetches external URLs for unauthenticated callers.

CVE-2026-54157GHSA-xmwj-c75x-6346CWE-918

Impact

Affected LobeHub deployments expose the /webapi/proxy route without authentication [S2]. The route can make outbound requests to attacker-selected external destinations and return the upstream response. The upstream advisory also describes response-header and cookie-injection impact.

Root Cause

In affected releases, the proxy route was not wrapped in the authentication check used by other LobeHub web API routes [S2]. LobeHub's URL-fetch helper includes private-address protections.

Technical Details

  • Vulnerability Type: Server-Side Request Forgery (SSRF) [S1]
  • Affected Endpoint: POST /webapi/proxy [S2]
  • Affected Versions: Up to and including 2.1.56 [S2]
  • Fixed Version: 2.1.57 [S2]
  • CVE ID: CVE-2026-54157 [S1]

How FixVibe covers it

FixVibe's verified active scans flag LobeHub deployments whose /webapi/proxy route fetches external URLs for unauthenticated callers, reported as a confirmed high-severity exposure associated with CVE-2026-54157.

Fix

Upgrade LobeHub to 2.1.57 or newer and restart the deployed service [S2]. Confirm that /webapi/proxy requires authentication or is removed. During rollout, restrict the LobeHub interface to trusted networks or authenticated reverse-proxy access, and review access logs for unexpected proxy requests.