A vulnerability classified as problematic was found in lobehub lobe-chat up to 2.2.13. This affects an unknown part of the component Avatar Upload Handler. Such manipulation leads to cross site scripting.

This vulnerability is uniquely identified as CVE-2026-72594. The attack can be launched remotely. No exploit exists.