DeepChat is a smart assistant uses artificial intelligence. In 0.5.0 and earlier, there is a Stored Cross-Site Scripting (XSS) vulnerability in the Mermaid diagram renderer allows an attacker to execute arbitrary JavaScript within the application context. By leveraging the exposed Electron IPC bridge, this XSS can be escalated to Remote Code Execution (RCE) by registering and starting a malicious MCP (Model Context Protocol) server.
Metrics
Affected Vendors & Products
References
History
Thu, 04 Dec 2025 16:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Thinkinai
Thinkinai deepchat |
|
| Vendors & Products |
Thinkinai
Thinkinai deepchat |
Wed, 03 Dec 2025 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 03 Dec 2025 19:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | DeepChat is a smart assistant uses artificial intelligence. In 0.5.0 and earlier, there is a Stored Cross-Site Scripting (XSS) vulnerability in the Mermaid diagram renderer allows an attacker to execute arbitrary JavaScript within the application context. By leveraging the exposed Electron IPC bridge, this XSS can be escalated to Remote Code Execution (RCE) by registering and starting a malicious MCP (Model Context Protocol) server. | |
| Title | DeepChat Cross-Site Scripting(XSS) escalate to Remote Code Execution(RCE) | |
| Weaknesses | CWE-94 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: GitHub_M
Published: 2025-12-03T18:34:44.019Z
Updated: 2025-12-03T19:10:17.039Z
Reserved: 2025-11-24T23:01:29.679Z
Link: CVE-2025-66222
Updated: 2025-12-03T19:10:11.921Z
Status : Awaiting Analysis
Published: 2025-12-03T19:15:58.237
Modified: 2025-12-04T17:15:08.283
Link: CVE-2025-66222
No data.