XSS Vulnerability in DeepChat AI Chat Platform by ThinkInAIXYZ
CVE-2025-66481
9.7CRITICAL
What is CVE-2025-66481?
DeepChat, an open-source AI chat platform created by ThinkInAIXYZ, suffers from a vulnerability that allows an attacker to execute cross-site scripting (XSS) attacks through improperly sanitized Mermaid content. Specifically, versions 0.5.1 and below are affected, permitting attackers to execute arbitrary code on victims' machines via the electron.ipcRenderer interface. This exploitation can bypass the existing security mechanisms intended to sanitize inputs, utilizing unquoted HTML attributes alongside HTML entity encoding. Despite the implementation of a recent security patch, it has proven inadequate at mitigating this risk, leaving users vulnerable until a comprehensive fix is provided.
Affected Version(s)
deepchat <= 0.5.1
