PT-2025-36955 · Deepchat · Deepchat
H3Rrr
·
Published
2025-09-09
·
Updated
2025-09-10
·
CVE-2025-58768
CVSS v3.1
9.6
Critical
| AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions:
DeepChat versions prior to 0.3.5
Description:
DeepChat, a smart assistant utilizing artificial intelligence, contains a flaw in the Mermaid chart rendering component. Directly using
innerHTML to set user content allows for the execution of malicious content. This issue stems from an insufficiently addressed cross-site scripting (XSS) problem, leading to an exploit chain that enables arbitrary JavaScript code execution via XSS and arbitrary commands via exposed Inter-Process Communication (IPC).Recommendations:
Update to version 0.3.5 or later.
Fix
XSS
Code Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Deepchat