Sunday, 13 September 2026
8 agent hacks today 7 vs yesterday (1)

LobeChat webhook signature verification bypass in QQ and Feishu adapters

LobeChat 2.2.1 fails to properly verify webhook signatures in QQ and Feishu adapters, allowing unauthenticated attackers to forge inbound messages and manipulate bot behavior by sending crafted requests to the unauthenticated webhook endpoint.

Disclosed 4 September 2026 · Record updated 13 September 2026

Impact

Unauthenticated attackers can forge inbound messages with attacker-chosen sender identity and arbitrary text, causing the bot to process attacker-controlled input as trusted platform messages.

Our coverage

No articles linked to this incident yet.

Sources

  1. github.comhttps://github.com/advisories/GHSA-627w-x4jq-g83v