XSS Vulnerability in DeepChat Smart Assistant by ThinkInAI
CVE-2025-58768
9.7CRITICAL
What is CVE-2025-58768?
DeepChat, an AI-powered smart assistant, contains a vulnerability in its Mermaid chart rendering component prior to version 0.3.5. The use of innerHTML
allows for the direct embedding of user content, which can be exploited to execute arbitrary JavaScript and commands through exposed IPC. This vulnerability stems from an inadequate resolution of an existing XSS issue, enabling an exploit chain that may compromise the application's security. The latest version, 0.3.5, includes critical updates addressing this flaw.
Affected Version(s)
deepchat < 0.3.5