PT-2025-49303 · Tuui · Tuui

Published

2025-12-05

·

Updated

2025-12-05

·

CVE-2025-66562

CVSS v3.1

9.6

Critical

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions TUUI versions prior to 1.3.4
Description TUUI is a desktop MCP client designed as a tool unitary utility integration. A critical Remote Code Execution (RCE) issue exists due to an unsafe Cross-Site Scripting (XSS) flaw in the Markdown rendering component. TUUI allows the execution of arbitrary JavaScript within ECharts code blocks. Combined with an exposed IPC interface that allows spawning processes, an attacker can execute arbitrary system commands on a victim’s machine by having them view a malicious Markdown message. The vulnerable component is the Markdown rendering component, specifically when processing ECharts code blocks.
Recommendations Versions prior to 1.3.4 should be updated to version 1.3.4 or later.

Exploit

Fix

RCE

XSS

Code Injection

Weakness Enumeration

Related Identifiers

CVE-2025-66562
GHSA-QJHQ-RGMR-6C3G

Affected Products

Tuui