Cross-Site Scripting Vulnerability in Lobe Chat Framework
CVE-2025-59417
What is CVE-2025-59417?
Lobe Chat, an open-source AI chat framework, exhibits a cross-site scripting vulnerability before version 1.129.4. This issue arises during the processing of chat messages where server responses containing specific lobeArtifact identifiers are improperly rendered. When an identifier of type image/svg+xml is processed, it leverages dangerouslySetInnerHTML, allowing malicious content to be injected and potentially escalated to remote code execution on a user's machine. Attackers can exploit this flaw by injecting harmful content into chat messages through various means, such as compromised servers or malicious web pages. The vulnerability has been addressed and resolved in version 1.129.4.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
lobe-chat < 1.129.4
References
CVSS V4
Timeline
Vulnerability published
Vulnerability Reserved
