PT-2025-21176 · 5Ire+1 · 5Ire+1

Published

2025-05-14

·

Updated

2025-05-19

·

CVE-2025-47777

CVSS v3.1

9.6

Critical

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions: 5ire versions prior to 0.11.1
Description: The issue is related to stored cross-site scripting in chatbot responses due to insufficient sanitization, which can lead to Remote Code Execution (RCE) via unsafe Electron protocol handling and exposed Electron APIs. Users of 5ire client versions prior to the patched release, particularly those interacting with untrusted chatbots or pasting external content, are affected.
Recommendations: For versions prior to 0.11.1, update to version 0.11.1 or later, which contains a patch for the issue. As a temporary workaround, consider avoiding interactions with untrusted chatbots and refraining from pasting external content until the update is applied. Restrict access to exposed Electron APIs to minimize the risk of exploitation.

Exploit

Fix

RCE

XSS

Weakness Enumeration

Related Identifiers

CVE-2025-47777
GHSA-MR8W-MMVV-6HQ8

Affected Products

5Ire
Electron