CVE-2026-23733

MEDIUM

lobehub chat < 2.0.0-next.180 - Stored Cross-Site Scripting and Remote Code Execution via Mermaid Artifact Renderer

Title source: llm
STIX 2.1

Description

LobeChat is an open source chat application platform. Prior to version 2.0.0-next.180, a stored Cross-Site Scripting (XSS) vulnerability in the Mermaid artifact renderer allows attackers to execute arbitrary JavaScript within the application context. This XSS can be escalated to Remote Code Execution (RCE) by leveraging the exposed `electronAPI` IPC bridge, allowing attackers to run arbitrary system commands on the victim's machine. Version 2.0.0-next.180 patches the issue.

References (1)

Core 1
Core References

Scores

CVSS v3 6.4
EPSS 0.0012
EPSS Percentile 2.4%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:H/PR:H/UI:R/S:C/C:H/I:L/A:L

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-94
Status published
Products (2)
lobehub/chat 0npm
lobehub/lobe-chat < 2.0.0-next.180
Published Jan 18, 2026
Tracked Since Feb 18, 2026