Vulnerability Description
LobeChat through 2.2.9 contains a broken object level authorization vulnerability that allows authenticated attackers to access and modify other users' chat-group agent data by supplying arbitrary group identifiers. Attackers can invoke the getGroupAgents, updateAgentInGroup, and removeAgentsFromGroup operations without user-scoped predicates to read agent listings, modify agent roles and ordering, and remove agents from chat groups belonging to other users.
CVSS Score
MEDIUM
Related Weaknesses (CWE)
References
- https://github.com/lobehub/lobehub/commit/9ed5a7e20d8a67c431265f5a252e9559d99209
- https://github.com/lobehub/lobehub/issues/16537
- https://github.com/lobehub/lobehub/pull/16586
- https://www.vulncheck.com/advisories/lobechat-broken-object-level-authorization-
FAQ
What is CVE-2026-59100?
CVE-2026-59100 is a vulnerability with a CVSS score of 5.0 (MEDIUM). LobeChat through 2.2.9 contains a broken object level authorization vulnerability that allows authenticated attackers to access and modify other users' chat-group agent data by supplying arbitrary gro...
How severe is CVE-2026-59100?
CVE-2026-59100 has been rated MEDIUM with a CVSS base score of 5.0/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-59100?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.