VYPR
Medium severity6.1NVD Advisory· Published Sep 18, 2025· Updated Jun 17, 2026

CVE-2025-59417

CVE-2025-59417

Description

Lobe Chat is an open-source artificial intelligence chat framework. Prior to version 1.129.4, there is a a cross-site scripting (XSS) vulnerability when handling chat message in lobe-chat that can be escalated to remote code execution on the user’s machine. In lobe-chat, when the response from the server is like , it will be rendered with the lobeArtifact node, instead of the plain text. However, when the type of the lobeArtifact is image/svg+xml , it will be rendered as the SVGRender component, which internally uses dangerouslySetInnerHTML to set the content of the svg, resulting in XSS attack. Any party capable of injecting content into chat messages, such as hosting a malicious page for prompt injection, operating a compromised MCP server, or leveraging tool integrations, can exploit this vulnerability. This vulnerability is fixed in 1.129.4.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
@lobehub/chatnpm
< 1.129.41.129.4

Affected products

3
  • Lobehub/Lobe Chat2 versions
    cpe:2.3:a:lobehub:lobe_chat:*:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:a:lobehub:lobe_chat:*:*:*:*:*:*:*:*range: <1.129.4
    • (no CPE)range: < 1.129.4
  • ghsa-coords
    Range: < 1.129.4

Patches

Vulnerability mechanics

References

9

News mentions

0

No linked articles in our index yet.