PT-2025-38409 · Lobe Chat · Lobe Chat
Jackfromeast
·
Published
2025-09-18
·
Updated
2025-09-18
·
CVE-2025-59417
CVSS v4.0
7.7
High
| Vector | AV:N/AC:H/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
Lobe Chat versions prior to 1.129.4
Description
Lobe Chat, an open-source artificial intelligence chat framework, contains a cross-site scripting (XSS) issue in how it handles chat messages. Specifically, when a server response includes a
lobeArtifact of type image/svg+xml, the application renders it using dangerouslySetInnerHTML, which can lead to XSS attacks. Parties capable of injecting content into chat messages – including malicious pages, compromised MCP servers, or tool integrations – can exploit this issue. This can potentially escalate to remote code execution on the user’s machine.Recommendations
Update Lobe Chat to version 1.129.4 or later.
Exploit
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Lobe Chat