Stored XSS Vulnerability in LobeChat Open Source Chat Application
CVE-2026-23733
6.4MEDIUM
What is CVE-2026-23733?
LobeChat is an open-source chat application that suffers from a stored Cross-Site Scripting (XSS) vulnerability found in the Mermaid artifact renderer. This flaw permits attackers to execute arbitrary JavaScript within the application's context. Additionally, it can be escalated to Remote Code Execution (RCE) by exploiting the electronAPI IPC bridge, allowing malicious actors to issue arbitrary commands on the victim's system. The issue has been addressed in version 2.0.0-next.180.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
lobe-chat < 2.0.0-next.180
References
CVSS V3.1
Score:
6.4
Severity:
MEDIUM
Confidentiality:
High
Integrity:
Low
Availability:
High
Attack Vector:
Local
Attack Complexity:
High
Privileges Required:
High
User Interaction:
Required
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved
