Stored XSS Vulnerability in LobeChat Open Source Chat Application
CVE-2026-23733
6.4MEDIUM
What is CVE-2026-23733?
LobeChat is an open-source chat application that suffers from a stored Cross-Site Scripting (XSS) vulnerability found in the Mermaid artifact renderer. This flaw permits attackers to execute arbitrary JavaScript within the application's context. Additionally, it can be escalated to Remote Code Execution (RCE) by exploiting the electronAPI IPC bridge, allowing malicious actors to issue arbitrary commands on the victim's system. The issue has been addressed in version 2.0.0-next.180.
Affected Version(s)
lobe-chat < 2.0.0-next.180
