PT-2025-21176 · 5Ire+1 · 5Ire+1
Published
2025-05-14
·
Updated
2025-05-19
·
CVE-2025-47777
CVSS v3.1
9.6
Critical
| Vector | AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions:
5ire versions prior to 0.11.1
Description:
The issue is related to stored cross-site scripting in chatbot responses due to insufficient sanitization, which can lead to Remote Code Execution (RCE) via unsafe Electron protocol handling and exposed Electron APIs. Users of 5ire client versions prior to the patched release, particularly those interacting with untrusted chatbots or pasting external content, are affected.
Recommendations:
For versions prior to 0.11.1, update to version 0.11.1 or later, which contains a patch for the issue. As a temporary workaround, consider avoiding interactions with untrusted chatbots and refraining from pasting external content until the update is applied. Restrict access to exposed Electron APIs to minimize the risk of exploitation.
Exploit
Fix
RCE
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
5Ire
Electron