Vulnerabilities/

LobeHub has a Cross-Site Scripting issue that escalates to Remote Code Execution

Severity:
Medium

Description

The vulnerability was automatically discovered by an ai agent and then manually verified.

LobeChat’s message rendering mechanism has a stored cross-site scripting (XSS) vulnerability.

Recommendation

No fix is available yet. Followings are affected versions:

References

Related Issues

Tags:
npm
@lobehub/lobehub
Anything's wrong? Let us know Last updated on May 13, 2026