PT-2025-33844 · Deepchat · Deepchat
Jackfromeast
·
Published
2025-08-19
·
Updated
2026-05-12
·
CVE-2025-55733
CVSS v3.1
9.6
Critical
| Vector | AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions:
DeepChat versions prior to 0.3.1
Description:
DeepChat is a smart assistant that connects powerful AI to a user’s personal world. A remote code execution flaw exists in versions prior to 0.3.1. An attacker can exploit this issue by embedding a specially crafted
deepchat: URL on a website. When a victim visits the site or clicks the link, the browser triggers the application’s custom URL handler, causing DeepChat to launch and process the URL, leading to remote code execution on the victim’s machine.Recommendations:
Update DeepChat to version 0.3.1 or later.
Exploit
Fix
RCE
Code Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Deepchat