XSS Vulnerability in DeepChat Smart Assistant by ThinkInAI
CVE-2025-58768
9.7CRITICAL
What is CVE-2025-58768?
DeepChat, an AI-powered smart assistant, contains a vulnerability in its Mermaid chart rendering component prior to version 0.3.5. The use of innerHTML allows for the direct embedding of user content, which can be exploited to execute arbitrary JavaScript and commands through exposed IPC. This vulnerability stems from an inadequate resolution of an existing XSS issue, enabling an exploit chain that may compromise the application's security. The latest version, 0.3.5, includes critical updates addressing this flaw.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
deepchat < 0.3.5
References
CVSS V3.1
Score:
9.7
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved
