CVE-2025-67744 is a critical remote code execution (RCE) vulnerability affecting DeepChat, an open-source AI agent platform, in versions prior to 0.5.3. This flaw stems from an unsafe Mermaid diagram rendering component and an exposed Electron IPC renderer, allowing arbitrary JavaScript execution that escalates to RCE. With a CVSS score of 9.6 (CRITICAL), this vulnerability can be exploited remotely with low complexity and user interaction, leading to complete compromise of confidentiality, integrity, and availability. While there is no known active exploitation or publicly available exploit code, the vulnerability has garnered some community attention, indicating potential future exploitation.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 0.5.3CPE matchmatch criteria | cpe:2.3:a:thinkinai:deepchat:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.8 Bluesky, 0.5 Mastodon, and 1.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.1 Security Researcher mentions.