PT-2025-49303 · Tuui · Tuui
Published
2025-12-05
·
Updated
2025-12-05
·
CVE-2025-66562
CVSS v3.1
9.6
Critical
| Vector | AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
TUUI versions prior to 1.3.4
Description
TUUI is a desktop MCP client designed as a tool unitary utility integration. A critical Remote Code Execution (RCE) issue exists due to an unsafe Cross-Site Scripting (XSS) flaw in the Markdown rendering component. TUUI allows the execution of arbitrary JavaScript within ECharts code blocks. Combined with an exposed IPC interface that allows spawning processes, an attacker can execute arbitrary system commands on a victim’s machine by having them view a malicious Markdown message. The vulnerable component is the Markdown rendering component, specifically when processing ECharts code blocks.
Recommendations
Versions prior to 1.3.4 should be updated to version 1.3.4 or later.
Exploit
Fix
RCE
XSS
Code Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Tuui