XSS and RCE Vulnerability in DeepChat AI Platform by ThinkInAI
CVE-2025-67744
9.7CRITICAL
What is CVE-2025-67744?
DeepChat, an open-source AI agent platform, is vulnerable to a significant security issue in its Mermaid diagram rendering component prior to version 0.5.3. This vulnerability allows for arbitrary JavaScript execution, primarily due to the Electron IPC renderer's exposure to the DOM. It creates a pathway for attackers to escalate the issue to full Remote Code Execution (RCE), enabling they execute arbitrary system commands. The vulnerability is rooted in unsafe configurations related to Mermaid and an exposed IPC interface, which have been addressed in the patched version 0.5.3.
Affected Version(s)
deepchat < 0.5.3
