CVE-2026-72594: Lobehub Lobe-Chat
High severity, CVSS 7.6. EPSS: 0.3% chance of exploitation in the next 30 days.
A stored cross-site scripting (XSS) vulnerability in lobehub/lobe-chat through v2.2.13 allows a low-privileged authenticated user to inject arbitrary JavaScript into the application by uploading a crafted SVG file as a user avatar.
Affected products
- Lobehub Lobe-Chat: up to and including 2.2.13
Published 2026-08-10. Last modified 2026-08-28.