PT-2025-36955 · Deepchat · Deepchat

H3Rrr

·

Published

2025-09-09

·

Updated

2025-09-10

·

CVE-2025-58768

CVSS v3.1

9.6

Critical

AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions: DeepChat versions prior to 0.3.5
Description: DeepChat, a smart assistant utilizing artificial intelligence, contains a flaw in the Mermaid chart rendering component. Directly using innerHTML to set user content allows for the execution of malicious content. This issue stems from an insufficiently addressed cross-site scripting (XSS) problem, leading to an exploit chain that enables arbitrary JavaScript code execution via XSS and arbitrary commands via exposed Inter-Process Communication (IPC).
Recommendations: Update to version 0.3.5 or later.

Fix

XSS

Code Injection

Weakness Enumeration

Related Identifiers

CVE-2025-58768
GHSA-F7Q5-VC93-WP6J

Affected Products

Deepchat