Description
The vulnerability was automatically discovered by an ai agent and then manually verified.
LobeChat’s message rendering mechanism has a stored cross-site scripting (XSS) vulnerability.
Recommendation
No fix is available yet. Followings are affected versions:
- <= 2.1.26
References
Could your website be exposed too?
SmartScanner can check your website for LobeHub has a Cross-Site Scripting issue that escalates to Remote Code Execution and gives you actionable findings to investigate.
Start a free scanRelated Issues
- Lobe Chat affected by Cross-Site Scripting(XSS) that can escalate to Remote Code Execution(RCE) - CVE-2026-23733
- Jodit has cross-site scripting (XSS) via <script> nested in SVG that bypasses clean-html sanitization - CVE-2026-65841
- beautiful-mermaid contains an SVG attribute injection issue that can lead to cross-site scripting (XSS) - CVE-2026-26226
- Angular's deprecated package has a Cross-Site Scripting issue - CVE-2026-11998
You might also like:
See something that needs correcting? Let us knowUpdated May 13, 2026


