CVE-2026-58578: Lobehub
Medium severity, CVSS 6.5. EPSS: 0.5% chance of exploitation in the next 30 days.
LobeChat before version 2.2.10-canary.15 contains a regular expression denial of service (ReDoS) vulnerability that allows authenticated attackers to block the Node.js event loop by supplying a catastrophic-backtracking pattern in a GitHub repository URL path during skill import. Attackers can craft a malicious basePath value containing unescaped regex metacharacters such as catastrophic-backtracking patterns, which are injected into a dynamically constructed regular expression in the findSkillMd function and executed synchronously against archive entries, denying service to all concurrent users for tens of seconds per request.
Affected products
- Lobehub Lobehub: before 2.2.10-canary.15 (fixed in 2.2.10-canary.15)
Published 2026-07-02. Last modified 2026-07-14.