CVE-2026-23733
LobeChat is an open source chat application platform. Prior to version 2.0.0-next.180, a stored Cross-Site Scripting (XSS) vulnerability in the Mermaid artifact renderer allows attackers to execute arbitrary JavaScript within the application context. This XSS can be escalated to Remote Code Execution (RCE) by leveraging the exposed `electronAPI` IPC bridge, allowing attackers to run arbitrary system commands on the victim's machine. Version 2.0.0-next.180 patches the issue.
- Affected products
- Lobe Chat, Mermaid, Electronapi
- Fix
- Available
- CVSS 3.1
- 6.4 MEDIUM
- EPSS
- 0.1% (2th percentile)
- Weakness
- CWE-94
- NVD status
- Deferred
- Published
- 2026-01-18
CVE-2026-23733 at NVD
No indexed exploits for CVE-2026-23733 yet
Our index is partial: it proves presence, never absence
No exploit for CVE-2026-23733 has been indexed yet. Our index is built from live traffic and upstream syncs, so this page can only say what it knows — not that no exploit exists.