Vulnerabilities/

Lobe Chat Desktop vulnerable to Remote Code Execution via XSS in Chat Messages

Severity:
Medium

Description

We identified a cross-site scripting (XSS) vulnerability when handling chat message in lobe-chat that can be escalated to remote code execution on the user’s machine.

Recommendation

Update the @lobehub/chat package to the latest compatible version. Followings are version details:

References

Related Issues

Tags:
npm
@lobehub/chat
Anything's wrong? Let us know Last updated on September 26, 2025

This issue is available in SmartScanner Professional

See Pricing