XSS and Command Injection Vulnerability in LobeHub by LobeHub
CVE-2026-42045

6.2MEDIUM

Key Information:

Vendor

Lobehub

Status
Vendor
CVE Published:
12 May 2026

What is CVE-2026-42045?

LobeHub, a collaborative platform, contains critical vulnerabilities prior to version 2.1.48 that pose significant security risks. The application fails to correctly handle custom tags in its rendering process, allowing attackers to craft malicious inputs that may trigger Cross-Site Scripting (XSS) attacks on the client side. Moreover, an exposed IPC interface, runCommand, in the Electron main process permits arbitrary command execution, which can be exploited if an attacker successfully compromises the application via XSS. The vulnerabilities allow an attacker to execute system commands with the user's privileges, potentially leading to severe data breaches and resource compromises. These issues have been addressed in the latest release to enhance system security.

Affected Version(s)

lobehub < 2.1.48

References

CVSS V3.1

Score:
6.2
Severity:
MEDIUM
Confidentiality:
High
Integrity:
Low
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
High
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.