PT-2025-52494 · Dive · Dive

·

CVE-2025-66580

·

Published

2025-12-19

·

Updated

2026-01-02

CVSS v3.1

9.6

Critical

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Dive versions prior to 0.11.1
Description Dive is an open-source MCP Host Desktop Application that integrates with function-calling LLMs. A critical Stored Cross-Site Scripting (XSS) issue exists in the Mermaid diagram rendering component. The application permits the execution of arbitrary JavaScript via javascript:. An attacker can exploit this to inject a malicious Model Context Protocol (MCP) server configuration, potentially leading to Remote Code Execution (RCE) on the victim's machine when a node is clicked. The vulnerable component allows for the injection of malicious code through the javascript: URI scheme.
Recommendations Update to version 0.11.1 to resolve this issue.

Exploit

Fix

RCE

XSS

Code Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-66580
GHSA-XV8M-365J-X6H2

Affected Products

Dive