Impact
Affected LobeHub deployments expose the /webapi/proxy route without authentication [S2]. The route can make outbound requests to attacker-selected external destinations and return the upstream response. The upstream advisory also describes response-header and cookie-injection impact.
Root Cause
In affected releases, the proxy route was not wrapped in the authentication check used by other LobeHub web API routes [S2]. LobeHub's URL-fetch helper includes private-address protections.
Technical Details
- Vulnerability Type: Server-Side Request Forgery (SSRF) [S1]
- Affected Endpoint:
POST /webapi/proxy[S2] - Affected Versions: Up to and including 2.1.56 [S2]
- Fixed Version: 2.1.57 [S2]
- CVE ID: CVE-2026-54157 [S1]
How FixVibe covers it
FixVibe's verified active scans flag LobeHub deployments whose /webapi/proxy route fetches external URLs for unauthenticated callers, reported as a confirmed high-severity exposure associated with CVE-2026-54157.
Fix
Upgrade LobeHub to 2.1.57 or newer and restart the deployed service [S2]. Confirm that /webapi/proxy requires authentication or is removed. During rollout, restrict the LobeHub interface to trusted networks or authenticated reverse-proxy access, and review access logs for unexpected proxy requests.
