DeepChat is an open-source AI chat platform that supports cloud models and LLMs. Versions 0.5.1 and below are vulnerable to XSS attacks through improperly sanitized Mermaid content. The recent security patch for MermaidArtifact.vue is insufficient and can be bypassed using unquoted HTML attributes combined with HTML entity encoding. Remote Code Execution is possible on the victim's machine via the electron.ipcRenderer interface, bypassing the regex filter intended to strip dangerous attributes. There is no fix at time of publication.
The vulnerability consists of the fact that the regex filter in the MermaidArtifact.vue file, intended to remove dangerous HTML attributes, can be bypassed using a combination of unquoted HTML attributes with HTML entity encoding. An attacker can inject a malicious XSS payload through crafted Mermaid content. Subsequently, using the electron.ipcRenderer interface available in the Electron environment, it is possible to escalate the XSS attack to full remote code execution (RCE) on the victim's device.
An attacker can execute arbitrary code on the victim's machine (RCE) through the electron.ipcRenderer interface, potentially gaining full control of the system. It is also possible to steal sensitive data (C:H) as well as modify or destroy data (I:H).
At the time of CVE publication (2025-12-09) no official patch exists. The producer's repository at https://github.com/ThinkInAIXYZ/deepchat should be monitored and patches applied immediately upon release. Until a fix is issued, it is recommended to limit application usage or disable Mermaid content support.
Thinkinai DeepChat in versions 0.5.1 and earlier
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:HThinkinai Deepchat
APPThinkinai≤ 0.5.1
Related vulnerabilities
RCE przez XSS w komponencie Mermaid w DeepChat (Electron IPC)
Stored XSS eskalowany do RCE w DeepChat poprzez renderer Mermaid
RCE przez XSS w komponencie Mermaid w aplikacji DeepChat
RCE jednym kliknięciem w DeepChat przez niebezpieczny handler URL