CVE-2025-66481 is a critical Cross-Site Scripting (XSS) vulnerability affecting DeepChat versions 0.5.1 and below, an open-source AI chat platform. This flaw, stemming from insufficient sanitization of Mermaid content, allows for Remote Code Execution (RCE) on a victim's machine by bypassing regex filters intended to strip dangerous attributes via the electron.ipcRenderer interface. With a CVSS score of 9.6 (CRITICAL), the vulnerability has a network attack vector, low attack complexity, and high impacts on confidentiality, integrity, and availability. There is no known fix at the time of publication, and while no active exploitation or public exploit code has been identified, the vulnerability has garnered community attention, with a single public mention highlighting its severity and the lack of a patch.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 0.5.1CPE matchmatch criteria | cpe:2.3:a:thinkinai:deepchat:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.8 Bluesky, 0.5 Mastodon, and 1.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.1 Security Researcher mentions.