XSS and RCE Vulnerability in DeepChat AI Platform by ThinkInAI
CVE-2025-67744
What is CVE-2025-67744?
DeepChat, an open-source AI agent platform, is vulnerable to a significant security issue in its Mermaid diagram rendering component prior to version 0.5.3. This vulnerability allows for arbitrary JavaScript execution, primarily due to the Electron IPC renderer's exposure to the DOM. It creates a pathway for attackers to escalate the issue to full Remote Code Execution (RCE), enabling they execute arbitrary system commands. The vulnerability is rooted in unsafe configurations related to Mermaid and an exposed IPC interface, which have been addressed in the patched version 0.5.3.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
deepchat < 0.5.3
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved
