PT-2025-33844 · Deepchat · Deepchat

Jackfromeast

·

Published

2025-08-19

·

Updated

2026-05-12

·

CVE-2025-55733

CVSS v3.1

9.6

Critical

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions: DeepChat versions prior to 0.3.1
Description: DeepChat is a smart assistant that connects powerful AI to a user’s personal world. A remote code execution flaw exists in versions prior to 0.3.1. An attacker can exploit this issue by embedding a specially crafted deepchat: URL on a website. When a victim visits the site or clicks the link, the browser triggers the application’s custom URL handler, causing DeepChat to launch and process the URL, leading to remote code execution on the victim’s machine.
Recommendations: Update DeepChat to version 0.3.1 or later.

Exploit

Fix

RCE

Code Injection

Weakness Enumeration

Related Identifiers

CVE-2025-55733
GHSA-HQR4-4GFC-5P2J

Affected Products

Deepchat