XSS Vulnerability in DeepChat AI Chat Platform by ThinkInAIXYZ
CVE-2025-66481

9.7CRITICAL

Key Information:

Status
Vendor
CVE Published:
9 December 2025

What is CVE-2025-66481?

DeepChat, an open-source AI chat platform created by ThinkInAIXYZ, suffers from a vulnerability that allows an attacker to execute cross-site scripting (XSS) attacks through improperly sanitized Mermaid content. Specifically, versions 0.5.1 and below are affected, permitting attackers to execute arbitrary code on victims' machines via the electron.ipcRenderer interface. This exploitation can bypass the existing security mechanisms intended to sanitize inputs, utilizing unquoted HTML attributes alongside HTML entity encoding. Despite the implementation of a recent security patch, it has proven inadequate at mitigating this risk, leaving users vulnerable until a comprehensive fix is provided.

Affected Version(s)

deepchat <= 0.5.1

References

CVSS V3.1

Score:
9.7
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.