Cross-Site Scripting Vulnerability in Lobe Chat Framework
CVE-2025-59417

6.8MEDIUM

Key Information:

Vendor

Lobehub

Status
Vendor
CVE Published:
18 September 2025

What is CVE-2025-59417?

Lobe Chat, an open-source AI chat framework, exhibits a cross-site scripting vulnerability before version 1.129.4. This issue arises during the processing of chat messages where server responses containing specific lobeArtifact identifiers are improperly rendered. When an identifier of type image/svg+xml is processed, it leverages dangerouslySetInnerHTML, allowing malicious content to be injected and potentially escalated to remote code execution on a user's machine. Attackers can exploit this flaw by injecting harmful content into chat messages through various means, such as compromised servers or malicious web pages. The vulnerability has been addressed and resolved in version 1.129.4.

Affected Version(s)

lobe-chat < 1.129.4

References

CVSS V4

Score:
6.8
Severity:
MEDIUM
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-59417 : Cross-Site Scripting Vulnerability in Lobe Chat Framework