LobeHub has a Cross-Site Scripting issue that escalates to Remote Code Execution
- Severity:
- Medium
Description
The vulnerability was automatically discovered by an ai agent and then manually verified.
LobeChat’s message rendering mechanism has a stored cross-site scripting (XSS) vulnerability.
Recommendation
No fix is available yet. Followings are affected versions:
- <= 2.1.26
References
Related Issues
- Lobe Chat affected by Cross-Site Scripting(XSS) that can escalate to Remote Code Execution(RCE) - CVE-2026-23733
- Jodit has cross-site scripting (XSS) via <script> nested in SVG that bypasses clean-html sanitization - CVE-2026-65841
- beautiful-mermaid contains an SVG attribute injection issue that can lead to cross-site scripting (XSS) - CVE-2026-26226
- Angular's deprecated package has a Cross-Site Scripting issue - CVE-2026-11998
You might also like:
- Tags:
- npm
- @lobehub/lobehub
Anything's wrong? Let us know Last updated on May 13, 2026


