PT-2025-48981 · Deepchat · Deepchat
Published
2025-12-03
·
Updated
2025-12-31
·
CVE-2025-66222
CVSS v3.1
9.6
Critical
| Vector | AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
DeepChat versions prior to 0.5.0
Description
DeepChat, an AI smart assistant, contains a Stored Cross-Site Scripting (XSS) issue within the Mermaid diagram renderer. This allows an attacker to execute arbitrary JavaScript code within the application's context. Exploitation of this XSS can be escalated to Remote Code Execution (RCE) by registering and initiating a malicious Model Context Protocol (MCP) server, leveraging the exposed Electron IPC bridge.
Recommendations
Update DeepChat to version 0.5.0 or later.
Exploit
Fix
RCE
XSS
Code Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Deepchat