PT-2025-52494 · Dive · Dive

C2An1

·

Published

2025-12-19

·

Updated

2026-01-02

·

CVE-2025-66580

CVSS v3.1

9.6

Critical

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Dive versions prior to 0.11.1
Description Dive is an open-source MCP Host Desktop Application that integrates with function-calling LLMs. A critical Stored Cross-Site Scripting (XSS) issue exists in the Mermaid diagram rendering component. The application permits the execution of arbitrary JavaScript via javascript:. An attacker can exploit this to inject a malicious Model Context Protocol (MCP) server configuration, potentially leading to Remote Code Execution (RCE) on the victim's machine when a node is clicked. The vulnerable component allows for the injection of malicious code through the javascript: URI scheme.
Recommendations Update to version 0.11.1 to resolve this issue.

Exploit

Fix

RCE

XSS

Code Injection

Weakness Enumeration

Related Identifiers

CVE-2025-66580
GHSA-XV8M-365J-X6H2

Affected Products

Dive