Looks like the Fedora package for OBS already has a fix in place for the code execution exploit.
However, you should still scrutinize your widgets to ensure that they aren’t vulnerable to XSS exploits as they can still act maliciously (do the pink test)
BTW, OBS in Fedora is not affected. Fedora has been shipping its OBS package with ~up to date CEF for a long time now.
Either way, this is only a risk if you use an unsafe or buggy chat widget. It doesn't mean everyone can get hacked through chat.