XSS Vulnerability in DeepChat Smart Assistant by ThinkInAI
CVE-2025-58768

9.7CRITICAL

Key Information:

Status
Vendor
CVE Published:
9 September 2025

What is CVE-2025-58768?

DeepChat, an AI-powered smart assistant, contains a vulnerability in its Mermaid chart rendering component prior to version 0.3.5. The use of innerHTML allows for the direct embedding of user content, which can be exploited to execute arbitrary JavaScript and commands through exposed IPC. This vulnerability stems from an inadequate resolution of an existing XSS issue, enabling an exploit chain that may compromise the application's security. The latest version, 0.3.5, includes critical updates addressing this flaw.

Affected Version(s)

deepchat < 0.3.5

References

CVSS V3.1

Score:
9.7
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-58768 : XSS Vulnerability in DeepChat Smart Assistant by ThinkInAI