Stored Cross-Site Scripting Vulnerability in Lobe Chat by Lobehub
CVE-2026-72594
7.6HIGH
What is CVE-2026-72594?
A stored cross-site scripting vulnerability exists in the Lobe Chat application by Lobehub. This vulnerability, present in version 2.2.13, enables a low-privileged authenticated user to upload a specially crafted SVG file as a user avatar. If successfully exploited, this could allow the attacker to inject arbitrary JavaScript into the application, potentially compromising user data and application integrity.
Affected Version(s)
lobe-chat 0 <= 2.2.13
