CRITICAL🇵🇱 Wersja polska

CVE-2025-55733

CVSS 9.6v3.1pub. 2025-08-19upd. 2025-09-17

DeepChat is a smart assistant that connects powerful AI to your personal world. DeepChat before 0.3.1 has a one-click remote code execution vulnerability. An attacker can exploit this vulnerability by embedding a specially crafted deepchat: URL on any website, including a malicious one they control. When a victim visits such a site or clicks on the link, the browser triggers the app’s custom URL handler (deepchat:), causing the DeepChat application to launch and process the URL, leading to remote code execution on the victim’s machine. This vulnerability is fixed in 0.3.1.

🤖 AI Analysis
How it works

The vulnerability stems from improper handling of a custom URL protocol handler (deepchat:) registered by the DeepChat application in the operating system. An attacker embeds a specially crafted URL with the deepchat: scheme on a website controlled by them. When the victim visits the site or clicks on the link, the browser passes control to the system handler, which launches the DeepChat application and passes the malicious payload to it. The application processes the URL content without proper validation, leading to code execution on the victim's machine (CWE-94 — improper control of generation of code).

Impact

Successful exploitation of the vulnerability allows an attacker to execute arbitrary code remotely (RCE) on the victim's machine in the context of the privileges of the running DeepChat process. With high impact ratings on confidentiality, integrity, and availability (all H), it is possible to gain full control over the victim's system.

Mitigation & patch

The DeepChat application should be updated immediately to version 0.3.1 or later, in which the vulnerability has been fixed. The vulnerability is removed in commit a0ff6f362e01ddceb7fd42d0af0b28b6184fb4d2. Until an update is applied, consider unregistering the custom deepchat: protocol handler from the operating system or restricting the application's ability to be launched by a browser.

Who is affected

DeepChat application (Thinkinai/ThinkInAIXYZ) in all versions prior to 0.3.1.

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
  • Thinkinai Deepchat

    APP
    Thinkinai
    0.3.0
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
RCE
CWE
References

Related vulnerabilities

CVE-2025-67744CRITICAL9.6PL ✓same product

RCE przez XSS w komponencie Mermaid w DeepChat (Electron IPC)

CVE-2025-66481CRITICAL9.6PL ✓same product

XSS i RCE w Thinkinai DeepChat przez nieskuteczną sanityzację Mermaid

CVE-2025-66222CRITICAL9.6PL ✓same product

Stored XSS eskalowany do RCE w DeepChat poprzez renderer Mermaid

CVE-2025-58768CRITICAL9.6PL ✓same product

RCE przez XSS w komponencie Mermaid w aplikacji DeepChat