CVE-2026-39411 | LobeHub up to 2.1.47 /webapi/chat/ improper authentication (GHSA-5mwj-v5jw-5c97)
A vulnerability was found in LobeHub up to 2.1.47. It has been rated as critical. Affected by this issue is some unknown functionality of the file /webapi/chat/. The manipulation leads to improper authentication.
This vulnerability is traded as CVE-2026-39411. It is possible to initiate the attack remotely. There is no exploit available.
Upgrading the affected component is advised.