CVE-2026-72594: Lobehub Lobe-Chat

High severity, CVSS 7.6. EPSS: 0.3% chance of exploitation in the next 30 days.

A stored cross-site scripting (XSS) vulnerability in lobehub/lobe-chat through v2.2.13 allows a low-privileged authenticated user to inject arbitrary JavaScript into the application by uploading a crafted SVG file as a user avatar.

Affected products

  • Lobehub Lobe-Chat: up to and including 2.2.13

Published 2026-08-10. Last modified 2026-08-28.