SCA: security update for @lobehub/chat (GHSA-wrrr-8jcv-wjf5)

high Tenable Cloud Security Plugin ID 437406

Description

There are packages installed that are affected by a vulnerability referenced in the following CVE:

- LobeHub is an open source human-and-AI-agent network. Prior to version 1.143.3, the file upload feature in
`Knowledge Base > File Upload` does not validate the integrity of the upload request, allowing users to
intercept and modify the request parameters. As a result, it is possible to create arbitrary files in
abnormal or unintended paths. In addition, since `lobechat.com` relies on the size parameter from the
request to calculate file usage, an attacker can manipulate this value to misrepresent the actual file
size, such as uploading a `1 GB` file while reporting it as `10 MB`, or falsely declaring a `10 MB` file
as a `1 GB` file. By manipulating the size value provided in the client upload request, it is possible to
bypass the monthly upload quota enforced by the server and continuously upload files beyond the intended
storage and traffic limits. This abuse can result in a discrepancy between actual resource consumption and
billing calculations, causing direct financial impact to the service operator. Additionally, exhaustion of
storage or related resources may lead to degraded service availability, including failed uploads, delayed
content delivery, or temporary suspension of upload functionality for legitimate users. A single malicious
user can also negatively affect other users or projects sharing the same subscription plan, effectively
causing an indirect denial of service (DoS). Furthermore, excessive and unaccounted-for uploads can
distort monitoring metrics and overload downstream systems such as backup processes, malware scanning, and
media processing pipelines, ultimately undermining overall operational stability and service reliability.
Version 1.143.3 contains a patch for the issue. (CVE-2026-23835)

See Also

https://github.com/advisories/GHSA-wrrr-8jcv-wjf5

Plugin Details

Severity: High

ID: 437406

Version: Revision 1.6

Type: Local

Family: SCA Checks

Published: 2/1/2026

Updated: 7/2/2026

Supported Sensors: Tenable Cloud Security, Tenable Self-Hosted Container Security

Risk Information

VPR

Risk Factor: Medium

Score: 4.3

Percentile: 53.59

Vendor

Vendor Severity: Medium

CVSS v2

Risk Factor: Medium

Base Score: 5.5

Temporal Score: 4.1

Vector: CVSS2#AV:N/AC:L/Au:S/C:N/I:P/A:P

CVSS Score Source: CVE-2026-23835

CVSS v3

Risk Factor: High

Base Score: 8.1

Temporal Score: 7.1

Vector: CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

CVSS v4

Risk Factor: High

Base Score: 7.2

Threat Score: 5.7

Threat Vector: CVSS:4.0/E:P

Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N

Vulnerability Information

Exploit Ease: No known exploits are available

Patch Publication Date: 2/1/2026

Vulnerability Publication Date: 1/30/2026

Reference Information

CVE: CVE-2026-23835

cwe: CWE-73