Description
A stored Cross-Site Scripting (XSS) vulnerability in the Mermaid artifact renderer allows attackers to execute arbitrary JavaScript within the application context. This XSS can be escalated to Remote Code Execution (RCE).
Recommendation
No fix is available yet. Followings are affected versions:
- <= 1.143.2
References
Could your website be exposed too?
SmartScanner can check your website for Lobe Chat affected by Cross-Site Scripting(XSS) that can escalate to Remote Code Execution(RCE) and gives you actionable findings to investigate.
Start a free scanRelated Issues
- LobeHub has a Cross-Site Scripting issue that escalates to Remote Code Execution - CVE-2026-42045
- beautiful-mermaid contains an SVG attribute injection issue that can lead to cross-site scripting (XSS) - CVE-2026-26226
- Lobe Chat Desktop vulnerable to Remote Code Execution via XSS in Chat Messages - CVE-2025-59417
- Lobe Chat has IDOR in Knowledge Base File Removal that Allows Cross User File Deletion - CVE-2026-23522


