CRITICAL🇵🇱 Wersja polska

CVE-2025-66222

CVSS 9.6v3.1pub. 2025-12-03upd. 2025-12-05

DeepChat is a smart assistant uses artificial intelligence. In 0.5.0 and earlier, there is a Stored Cross-Site Scripting (XSS) vulnerability in the Mermaid diagram renderer allows an attacker to execute arbitrary JavaScript within the application context. By leveraging the exposed Electron IPC bridge, this XSS can be escalated to Remote Code Execution (RCE) by registering and starting a malicious MCP (Model Context Protocol) server.

🤖 AI Analysis
How it works

An attacker injects malicious JavaScript code through the vulnerable Mermaid diagram renderer, which stores the payload in the application context (Stored XSS). When the victim displays the infected content, the malicious script is executed within the Electron application. The attacker then exploits access to the IPC bridge (Inter-Process Communication) exposed by Electron to register and run a malicious MCP server (Model Context Protocol), leading to arbitrary code execution at the operating system level.

Impact

An attacker can gain full control over the victim's system, including reading sensitive data, modifying files, and executing arbitrary system commands (RCE). Compromise of confidentiality, integrity, and availability of the system is complete.

Mitigation & patch

Security patches available from the vendor should be applied according to the references. A fix is available in the project's GitHub repository in commit 371ca7b42e3685aee6e3f0c61e85277ed1ff4db7. It is recommended to update to a version higher than 0.5.0 immediately upon its release.

Who is affected

Thinkinai DeepChat application version 0.5.0 and earlier.

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
  • Thinkinai Deepchat

    APP
    Thinkinai
    ≤ 0.5.0
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
RCEXSS
CWE
References

Related vulnerabilities

CVE-2025-67744CRITICAL9.6PL ✓same product

RCE przez XSS w komponencie Mermaid w DeepChat (Electron IPC)

CVE-2025-66481CRITICAL9.6PL ✓same product

XSS i RCE w Thinkinai DeepChat przez nieskuteczną sanityzację Mermaid

CVE-2025-58768CRITICAL9.6PL ✓same product

RCE przez XSS w komponencie Mermaid w aplikacji DeepChat

CVE-2025-55733CRITICAL9.6PL ✓same product

RCE jednym kliknięciem w DeepChat przez niebezpieczny handler URL