CVE-2026-72594: lobehub lobe-chat - Stored Cross-Site Scripting via Unrestricted SVG Avatar Upload

Published Aug 10, 2026
·
Updated

A stored cross-site scripting (XSS) vulnerability in lobehub/lobe-chat through v2.2.13 allows a low-privileged authenticated user to inject arbitrary JavaScript into the application by uploading a crafted SVG file as a user avatar.

Affected Software

1 affected component
lobehub/lobe-chat<=2.2.13

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Configuration

    Change the avatar upload handler logic to determine allowed content types by inspecting the uploaded file content (not by using the original filename-derived stored file extension and S3 content type) so that SVG with script elements is not accepted.

    lobe-chat avatar upload handler MIME type / file type validation = derived from original filename
  2. Compensating control

    Block or restrict SVG file uploads for user avatars (e.g., reject files with .svg extension) to prevent stored XSS via crafted SVG avatar images.

Event History

Aug 10, 2026
CVE Published
via MITRE·10:41 AM
Data Sourced
via MITRE·10:41 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·11:17 AM
DescriptionSeverityWeakness
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2026-72594?

The severity of CVE-2026-72594 is rated as high with a score of 7.6.

2

How do I fix CVE-2026-72594?

To fix CVE-2026-72594, ensure that user-uploaded SVG files are properly sanitized and validate the file extensions before processing.

3

Who is affected by CVE-2026-72594?

CVE-2026-72594 affects low-privileged authenticated users of the lobehub/lobe-chat application.

4

What type of vulnerability is CVE-2026-72594?

CVE-2026-72594 is a stored cross-site scripting (XSS) vulnerability.

5

What can an attacker do with CVE-2026-72594?

An attacker can inject arbitrary JavaScript into the application by uploading a crafted SVG file as a user avatar.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203