StackRadar

CVE-2026-23522

Low

Advisory

Published 20 Jan 2026In the index since 8 Sept 2026
Severity
Low
worst across findings
CVSS
3.7
base score, highest
EPSS
0.002
11th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
1
of 17,781 indexed, latest versions
Container images
1
deployed by those charts
Fix available
None
affected package

Lobe Chat has IDOR in Knowledge Base File Removal that Allows Cross User File Deletion

Carried by container images the latest versions of 1 of 17,781 indexed charts deploy, on 1 image.

Affected packageAffected versionsFixed inImages
@lobehub/chatnpm1.96.9no fix listed1
OSV records
GHSA-j7xp-4mg9-x28r

Charts affected

1 by stars
ChartLatestAffected imagesRadar Score
lobe-chathelm-charts-darox0.1.561 of 1See more

lobe-chat helm-charts-darox 0.1.56

1 of the 1 container images this version deploys carry CVE-2026-23522.

Container imageDigestPackageFixed in
lobehub/lobe-chat:1.96.9da0c21fefcd3
@lobehub/chat@1.96.9
no fix listed

Open the chart page →

666

Container images carrying it

1 by charts deploying them

A fixed version is listed for 0 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
lobehub/lobe-chat:1.96.9da0c21fefcd3
@lobehub/chat@1.96.9
no fix listed
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.