9.7
/ 10
CRITICAL
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
Description
DeepChat is an open-source AI chat platform that supports cloud models and LLMs. Versions 0.5.1 and below are vulnerable to XSS attacks through improperly sanitized Mermaid content. The recent security patch for MermaidArtifact.vue is insufficient and can be bypassed using unquoted HTML attributes combined with HTML entity encoding. Remote Code Execution is possible on the victim's machine via the electron.ipcRenderer interface, bypassing the regex filter intended to strip dangerous attributes. There is no fix at time of publication.
AI Analysis
XSS vulnerability in DeepChat through improperly sanitized Mermaid content, allowing Remote Code Execution via electron.ipcRenderer interface
Basic Information
ID
CVE-2025-66481
Source
GitHub_M
Published
Dec 9, 2025 at 00:25
Affected Product
Vendor
ThinkInAIXYZ
Product
deepchat
Version
<= 0.5.1
Affected Versions
ThinkInAIXYZ deepchat <= 0.5.1
CWE Classification
AI Assessment
AI Score
9.7 / 10
AI Severity
Critical
Vendor
ThinkInAIXYZ
Product
DeepChat
Version
0.5.1 and below