Cross-Site Scripting Vulnerability in Lobe Chat Framework
CVE-2025-59417
6.8MEDIUM
What is CVE-2025-59417?
Lobe Chat, an open-source AI chat framework, exhibits a cross-site scripting vulnerability before version 1.129.4. This issue arises during the processing of chat messages where server responses containing specific lobeArtifact identifiers are improperly rendered. When an identifier of type image/svg+xml is processed, it leverages dangerouslySetInnerHTML, allowing malicious content to be injected and potentially escalated to remote code execution on a user's machine. Attackers can exploit this flaw by injecting harmful content into chat messages through various means, such as compromised servers or malicious web pages. The vulnerability has been addressed and resolved in version 1.129.4.
Affected Version(s)
lobe-chat < 1.129.4