Thinkinai develops DeepChat, a web-based conversational interface component whose vulnerability footprint centers on client-side code-injection and cross-site scripting weaknesses arising from input handling and HTML sanitization. These application-layer flaws are typical of interactive web components that parse and render user-supplied content; current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Thinkinai over time
Signals from CVEs in this vendor scope (5 CVEs).
5 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-66222CRITICAL DeepChat is a smart assistant uses artificial intelligence. In 0.5.0 and earlier, there is a Stored Cross-Site Scripting (XSS) vulnerability in the Mermaid diagram renderer allows | Dec 3, 2025 | 9.6 | 33 | NO | NO |
CVE-2025-67744CRITICAL DeepChat is an open-source artificial intelligence agent platform that unifies models, tools, and agents. Prior to version 0.5.3, a security vulnerability exists in the Mermaid dia | Dec 16, 2025 | 9.6 | 32 | NO | NO |
CVE-2025-66481CRITICAL DeepChat is an open-source AI chat platform that supports cloud models and LLMs. Versions 0.5.1 and below are vulnerable to XSS attacks through improperly sanitized Mermaid content | Dec 9, 2025 | 9.6 | 32 | NO | NO |
CVE-2025-55733CRITICAL DeepChat is a smart assistant that connects powerful AI to your personal world. DeepChat before 0.3.1 has a one-click remote code execution vulnerability. An attacker can exploit | Aug 19, 2025 | 9.6 | 32 | NO | NO |
CVE-2025-58768CRITICAL DeepChat is a smart assistant uses artificial intelligence. Prior to version 0.3.5, in the Mermaid chart rendering component, there is a risky operation of directly using `innerHTM | Sep 9, 2025 | 9.6 | 30 | NO | NO |
Signals from CVEs in this vendor scope (5 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Thinkinai.
Media articles that mention a CVE ID that affects a product developed by Thinkinai — matched by CVE ID, not by vendor name.