Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2025-59417

21
FAUCET Score

CVE-2025-59417 is a cross-site scripting (XSS) vulnerability in Lobe Chat, an open-source AI chat framework, affecting versions prior to 1.129.4. This flaw allows for remote code execution on a user's machine due to improper handling of SVG content within chat messages. With a CVSS score of 6.1 (Medium), exploitation requires user interaction (UI:R) and can lead to low impact on confidentiality and integrity. While the EPSS score is low, indicating a low probability of exploitation, there is currently no public exploit code, active exploitation, or significant community discussion surrounding this vulnerability.

Impacted Technologies

VendorProductVersion(s)CPE
< 1.129.4CPE matchmatch criteria
cpe:2.3:a:lobehub:lobe_chat:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 4.0

6.8MEDIUM

CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

Attack Vector
NETWORK
Attack Complexity
HIGH
Attack Requirements
NONE
Privileges Required
NONE
User Interaction
PASSIVE
VS Confidentiality
HIGH
VS Integrity
HIGH
VS Availability
HIGH
SS Confidentiality
NONE
SS Integrity
NONE
SS Availability
NONE
Exploit Maturity
PROOF_OF_CONCEPT
CvssVersion
4.0

Exploit Intelligence

EPSS Score
0.36%
Probability of exploitation in next 30 days
EPSS Percentile
29.1%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0037 is in the 30th percentile among its peer group of 26,221 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (2)

github_advisorypatch availablevia nvd_reference
View patch
npmpatch availablevia ghsa
Product: @lobehub/chatFixed in: 1.129.4

Vendor Advisories (1)

npmGHSA-m79r-r765-5f9jmedium

Lobe Chat Desktop vulnerable to Remote Code Execution via XSS in Chat Messages

Sep 18, 2025

References

github.com / lobehub/lobe-chat/commit/9f044edd07ce102fe9f4b2fb47c62191c36da05c
Patch
github.com / lobehub/lobe-chat/security/advisories/GHSA-m79r-r765-5f9j
ExploitVendor Advisory