XSS and Command Injection Vulnerability in LobeHub by LobeHub
CVE-2026-42045
What is CVE-2026-42045?
LobeHub, a collaborative platform, contains critical vulnerabilities prior to version 2.1.48 that pose significant security risks. The application fails to correctly handle custom tags in its rendering process, allowing attackers to craft malicious inputs that may trigger Cross-Site Scripting (XSS) attacks on the client side. Moreover, an exposed IPC interface, runCommand, in the Electron main process permits arbitrary command execution, which can be exploited if an attacker successfully compromises the application via XSS. The vulnerabilities allow an attacker to execute system commands with the user's privileges, potentially leading to severe data breaches and resource compromises. These issues have been addressed in the latest release to enhance system security.
Affected Version(s)
lobehub < 2.1.48
