XSS and RCE Vulnerability in DeepChat AI Platform by ThinkInAI
CVE-2025-67744

9.7CRITICAL

Key Information:

Status
Vendor
CVE Published:
16 December 2025

What is CVE-2025-67744?

DeepChat, an open-source AI agent platform, is vulnerable to a significant security issue in its Mermaid diagram rendering component prior to version 0.5.3. This vulnerability allows for arbitrary JavaScript execution, primarily due to the Electron IPC renderer's exposure to the DOM. It creates a pathway for attackers to escalate the issue to full Remote Code Execution (RCE), enabling they execute arbitrary system commands. The vulnerability is rooted in unsafe configurations related to Mermaid and an exposed IPC interface, which have been addressed in the patched version 0.5.3.

Affected Version(s)

deepchat < 0.5.3

References

CVSS V3.1

Score:
9.7
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-67744 : XSS and RCE Vulnerability in DeepChat AI Platform by ThinkInAI