{"id":"CVE-2024-24566","summary":"Lobe Chat unauthorized access to plugins","details":"Lobe Chat is a chatbot framework that supports speech synthesis, multimodal, and extensible Function Call plugin system. When the application is password-protected (deployed with the `ACCESS_CODE` option), it is possible to access plugins without proper authorization (without password). This vulnerability is patched in 0.122.4.","aliases":["GHSA-pf55-fj96-xf37"],"modified":"2026-04-10T05:11:54.300717Z","published":"2024-01-31T16:33:44.129Z","database_specific":{"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2024/24xxx/CVE-2024-24566.json","cwe_ids":["CWE-284"],"cna_assigner":"GitHub_M"},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2024/24xxx/CVE-2024-24566.json"},{"type":"ADVISORY","url":"https://github.com/lobehub/lobe-chat/security/advisories/GHSA-pf55-fj96-xf37"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2024-24566"},{"type":"FIX","url":"https://github.com/lobehub/lobe-chat/commit/2184167f09ab68e4efa051ee984ea0c4e7c48fbd"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/lobehub/lobe-chat","events":[{"introduced":"0"},{"fixed":"36125f4f46b37bda2f674c1c24fbd57479e4327d"}]}],"versions":["v0.1.5","v0.10.0","v0.10.1","v0.10.2","v0.100.0","v0.100.1","v0.100.2","v0.100.3","v0.100.4","v0.100.5","v0.101.0","v0.101.1","v0.101.2","v0.101.3","v0.101.4","v0.101.5","v0.101.6","v0.101.7","v0.102.0","v0.102.1","v0.102.2","v0.102.3","v0.102.4","v0.103.0","v0.103.1","v0.104.0","v0.105.0","v0.105.1","v0.105.2","v0.106.0","v0.107.0","v0.107.1","v0.107.10","v0.107.11","v0.107.12","v0.107.13","v0.107.14","v0.107.15","v0.107.16","v0.107.2","v0.107.3","v0.107.4","v0.107.5","v0.107.6","v0.107.7","v0.107.8","v0.107.9","v0.108.0","v0.109.0","v0.109.1","v0.11.0","v0.110.0","v0.110.1","v0.110.10","v0.110.2","v0.110.3","v0.110.4","v0.110.5","v0.110.6","v0.110.7","v0.110.8","v0.110.9","v0.111.0","v0.111.1","v0.111.2","v0.111.3","v0.111.4","v0.111.5","v0.111.6","v0.112.0","v0.112.1","v0.113.0","v0.113.1","v0.114.0","v0.114.1","v0.114.2","v0.114.3","v0.114.4","v0.114.5","v0.114.6","v0.114.7","v0.114.8","v0.114.9","v0.115.0","v0.115.1","v0.115.10","v0.115.11","v0.115.12","v0.115.13","v0.115.2","v0.115.3","v0.115.4","v0.115.5","v0.115.6","v0.115.7","v0.115.8","v0.115.9","v0.116.0","v0.116.1","v0.116.2","v0.116.3","v0.116.4","v0.116.5","v0.117.0","v0.117.1","v0.117.2","v0.117.3","v0.117.4","v0.117.5","v0.118.0","v0.118.1","v0.118.10","v0.118.2","v0.118.3","v0.118.4","v0.118.5","v0.118.6","v0.118.7","v0.118.8","v0.118.9","v0.119.0","v0.119.1","v0.119.10","v0.119.11","v0.119.12","v0.119.13","v0.119.2","v0.119.3","v0.119.4","v0.119.5","v0.119.6","v0.119.7","v0.119.8","v0.119.9","v0.12.0","v0.12.1","v0.120.0","v0.120.1","v0.120.2","v0.120.3","v0.120.4","v0.120.5","v0.120.6","v0.121.0","v0.121.1","v0.121.2","v0.121.3","v0.121.4","v0.122.0","v0.122.1","v0.122.2","v0.122.3","v0.13.0","v0.13.1","v0.14.0","v0.15.0","v0.15.1","v0.16.0","v0.16.1","v0.17.0","v0.18.0","v0.18.1","v0.18.2","v0.19.0","v0.2.0","v0.20.0","v0.21.0","v0.22.0","v0.22.1","v0.22.2","v0.23.0","v0.25.0","v0.26.0","v0.26.1","v0.27.0","v0.27.1","v0.27.2","v0.27.3","v0.27.4","v0.28.0","v0.29.0","v0.3.0","v0.30.0","v0.30.1","v0.31.0","v0.32.0","v0.33.0","v0.35.0","v0.35.1","v0.36.0","v0.36.1","v0.37.0","v0.38.0","v0.39.0","v0.39.1","v0.39.2","v0.39.3","v0.4.0","v0.4.2","v0.4.3","v0.40.0","v0.40.1","v0.40.2","v0.40.3","v0.40.4","v0.40.5","v0.40.6","v0.40.7","v0.41.0","v0.41.1","v0.41.2","v0.42.0","v0.42.1","v0.42.2","v0.42.3","v0.43.0","v0.44.0","v0.44.1","v0.44.2","v0.44.3","v0.44.4","v0.46.0","v0.46.1","v0.47.0","v0.48.0","v0.49.0","v0.5.0","v0.50.0","v0.51.0","v0.52.0","v0.52.1","v0.53.0","v0.54.0","v0.54.1","v0.54.2","v0.54.3","v0.54.4","v0.55.0","v0.55.1","v0.56.0","v0.57.0","v0.58.0","v0.59.0","v0.6.0","v0.6.1","v0.60.0","v0.60.1","v0.60.2","v0.60.3","v0.60.4","v0.61.0","v0.62.0","v0.62.1","v0.63.0","v0.63.1","v0.63.2","v0.63.3","v0.64.0","v0.64.1","v0.65.0","v0.65.1","v0.66.0","v0.67.0","v0.68.0","v0.68.1","v0.69.0","v0.69.1","v0.7.0","v0.70.0","v0.70.1","v0.70.2","v0.70.3","v0.70.4","v0.71.0","v0.71.1","v0.72.0","v0.72.1","v0.72.2","v0.72.3","v0.72.4","v0.73.0","v0.74.0","v0.75.0","v0.76.0","v0.76.1","v0.76.2","v0.77.0","v0.77.1","v0.77.2","v0.78.0","v0.78.1","v0.79.0","v0.79.1","v0.79.2","v0.79.3","v0.79.4","v0.79.5","v0.79.6","v0.79.7","v0.79.8","v0.8.0","v0.8.1","v0.8.2","v0.80.0","v0.80.1","v0.80.2","v0.81.0","v0.82.0","v0.82.1","v0.82.2","v0.82.3","v0.82.4","v0.82.5","v0.82.6","v0.82.7","v0.82.8","v0.82.9","v0.83.0","v0.83.1","v0.83.10","v0.83.2","v0.83.3","v0.83.4","v0.83.5","v0.83.6","v0.83.7","v0.83.8","v0.83.9","v0.84.0","v0.85.0","v0.85.1","v0.85.2","v0.85.3","v0.86.0","v0.86.1","v0.86.2","v0.86.3","v0.86.4","v0.86.5","v0.87.0","v0.88.0","v0.89.0","v0.89.1","v0.89.10","v0.89.2","v0.89.3","v0.89.4","v0.89.5","v0.89.6","v0.89.7","v0.89.8","v0.89.9","v0.9.0","v0.90.0","v0.90.1","v0.90.2","v0.90.3","v0.91.0","v0.92.0","v0.93.0","v0.94.0","v0.94.1","v0.94.2","v0.94.3","v0.94.4","v0.94.5","v0.95.0","v0.95.1","v0.96.0","v0.96.1","v0.96.2","v0.96.3","v0.96.4","v0.96.5","v0.96.6","v0.96.7","v0.96.8","v0.96.9","v0.97.0","v0.97.1","v0.98.0","v0.98.1","v0.98.2","v0.98.3","v0.99.0","v0.99.1","v1.0.0"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2024-24566.json"}},{"ranges":[{"type":"GIT","repo":"https://github.com/lobehub/lobehub","events":[{"introduced":"0"},{"fixed":"2184167f09ab68e4efa051ee984ea0c4e7c48fbd"}]}],"versions":["v0.1.5","v0.10.0","v0.10.1","v0.10.2","v0.100.0","v0.100.1","v0.100.2","v0.100.3","v0.100.4","v0.100.5","v0.101.0","v0.101.1","v0.101.2","v0.101.3","v0.101.4","v0.101.5","v0.101.6","v0.101.7","v0.102.0","v0.102.1","v0.102.2","v0.102.3","v0.102.4","v0.103.0","v0.103.1","v0.104.0","v0.105.0","v0.105.1","v0.105.2","v0.106.0","v0.107.0","v0.107.1","v0.107.10","v0.107.11","v0.107.12","v0.107.13","v0.107.14","v0.107.15","v0.107.16","v0.107.2","v0.107.3","v0.107.4","v0.107.5","v0.107.6","v0.107.7","v0.107.8","v0.107.9","v0.108.0","v0.109.0","v0.109.1","v0.11.0","v0.110.0","v0.110.1","v0.110.10","v0.110.2","v0.110.3","v0.110.4","v0.110.5","v0.110.6","v0.110.7","v0.110.8","v0.110.9","v0.111.0","v0.111.1","v0.111.2","v0.111.3","v0.111.4","v0.111.5","v0.111.6","v0.112.0","v0.112.1","v0.113.0","v0.113.1","v0.114.0","v0.114.1","v0.114.2","v0.114.3","v0.114.4","v0.114.5","v0.114.6","v0.114.7","v0.114.8","v0.114.9","v0.115.0","v0.115.1","v0.115.10","v0.115.11","v0.115.12","v0.115.13","v0.115.2","v0.115.3","v0.115.4","v0.115.5","v0.115.6","v0.115.7","v0.115.8","v0.115.9","v0.116.0","v0.116.1","v0.116.2","v0.116.3","v0.116.4","v0.116.5","v0.117.0","v0.117.1","v0.117.2","v0.117.3","v0.117.4","v0.117.5","v0.118.0","v0.118.1","v0.118.10","v0.118.2","v0.118.3","v0.118.4","v0.118.5","v0.118.6","v0.118.7","v0.118.8","v0.118.9","v0.119.0","v0.119.1","v0.119.10","v0.119.11","v0.119.12","v0.119.13","v0.119.2","v0.119.3","v0.119.4","v0.119.5","v0.119.6","v0.119.7","v0.119.8","v0.119.9","v0.12.0","v0.12.1","v0.120.0","v0.120.1","v0.120.2","v0.120.3","v0.120.4","v0.120.5","v0.120.6","v0.121.0","v0.121.1","v0.121.2","v0.121.3","v0.121.4","v0.122.0","v0.122.1","v0.122.2","v0.122.3","v0.13.0","v0.13.1","v0.14.0","v0.15.0","v0.15.1","v0.16.0","v0.16.1","v0.17.0","v0.18.0","v0.18.1","v0.18.2","v0.19.0","v0.2.0","v0.20.0","v0.21.0","v0.22.0","v0.22.1","v0.22.2","v0.23.0","v0.25.0","v0.26.0","v0.26.1","v0.27.0","v0.27.1","v0.27.2","v0.27.3","v0.27.4","v0.28.0","v0.29.0","v0.3.0","v0.30.0","v0.30.1","v0.31.0","v0.32.0","v0.33.0","v0.35.0","v0.35.1","v0.36.0","v0.36.1","v0.37.0","v0.38.0","v0.39.0","v0.39.1","v0.39.2","v0.39.3","v0.4.0","v0.4.2","v0.4.3","v0.40.0","v0.40.1","v0.40.2","v0.40.3","v0.40.4","v0.40.5","v0.40.6","v0.40.7","v0.41.0","v0.41.1","v0.41.2","v0.42.0","v0.42.1","v0.42.2","v0.42.3","v0.43.0","v0.44.0","v0.44.1","v0.44.2","v0.44.3","v0.44.4","v0.46.0","v0.46.1","v0.47.0","v0.48.0","v0.49.0","v0.5.0","v0.50.0","v0.51.0","v0.52.0","v0.52.1","v0.53.0","v0.54.0","v0.54.1","v0.54.2","v0.54.3","v0.54.4","v0.55.0","v0.55.1","v0.56.0","v0.57.0","v0.58.0","v0.59.0","v0.6.0","v0.6.1","v0.60.0","v0.60.1","v0.60.2","v0.60.3","v0.60.4","v0.61.0","v0.62.0","v0.62.1","v0.63.0","v0.63.1","v0.63.2","v0.63.3","v0.64.0","v0.64.1","v0.65.0","v0.65.1","v0.66.0","v0.67.0","v0.68.0","v0.68.1","v0.69.0","v0.69.1","v0.7.0","v0.70.0","v0.70.1","v0.70.2","v0.70.3","v0.70.4","v0.71.0","v0.71.1","v0.72.0","v0.72.1","v0.72.2","v0.72.3","v0.72.4","v0.73.0","v0.74.0","v0.75.0","v0.76.0","v0.76.1","v0.76.2","v0.77.0","v0.77.1","v0.77.2","v0.78.0","v0.78.1","v0.79.0","v0.79.1","v0.79.2","v0.79.3","v0.79.4","v0.79.5","v0.79.6","v0.79.7","v0.79.8","v0.8.0","v0.8.1","v0.8.2","v0.80.0","v0.80.1","v0.80.2","v0.81.0","v0.82.0","v0.82.1","v0.82.2","v0.82.3","v0.82.4","v0.82.5","v0.82.6","v0.82.7","v0.82.8","v0.82.9","v0.83.0","v0.83.1","v0.83.10","v0.83.2","v0.83.3","v0.83.4","v0.83.5","v0.83.6","v0.83.7","v0.83.8","v0.83.9","v0.84.0","v0.85.0","v0.85.1","v0.85.2","v0.85.3","v0.86.0","v0.86.1","v0.86.2","v0.86.3","v0.86.4","v0.86.5","v0.87.0","v0.88.0","v0.89.0","v0.89.1","v0.89.10","v0.89.2","v0.89.3","v0.89.4","v0.89.5","v0.89.6","v0.89.7","v0.89.8","v0.89.9","v0.9.0","v0.90.0","v0.90.1","v0.90.2","v0.90.3","v0.91.0","v0.92.0","v0.93.0","v0.94.0","v0.94.1","v0.94.2","v0.94.3","v0.94.4","v0.94.5","v0.95.0","v0.95.1","v0.96.0","v0.96.1","v0.96.2","v0.96.3","v0.96.4","v0.96.5","v0.96.6","v0.96.7","v0.96.8","v0.96.9","v0.97.0","v0.97.1","v0.98.0","v0.98.1","v0.98.2","v0.98.3","v0.99.0","v0.99.1","v1.0.0"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2024-24566.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N"}]}