LobeChat webhook signature verification bypass in QQ and Feishu adapters
LobeChat 2.2.1 fails to properly verify webhook signatures in QQ and Feishu adapters, allowing unauthenticated attackers to forge inbound messages and manipulate bot behavior by sending crafted requests to the unauthenticated webhook endpoint.
Disclosed 4 September 2026 · Record updated 13 September 2026
Impact
Unauthenticated attackers can forge inbound messages with attacker-chosen sender identity and arbitrary text, causing the bot to process attacker-controlled input as trusted platform messages.
Our coverage
No articles linked to this incident yet.
Sources
- github.comhttps://github.com/advisories/GHSA-627w-x4jq-g83v
