DeepChat is an open-source AI chat platform that supports cloud models and LLMs. Versions 0.5.1 and below are vulnerable to XSS attacks through improperly sanitized Mermaid content. The recent security patch for MermaidArtifact.vue is insufficient and can be bypassed using unquoted HTML attributes combined with HTML entity encoding. Remote Code Execution is possible on the victim's machine via the electron.ipcRenderer interface, bypassing the regex filter intended to strip dangerous attributes. There is no fix at time of publication.
Advisories

No advisories yet.

Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Fri, 12 Dec 2025 04:00:00 +0900

Type Values Removed Values Added
CPEs cpe:2.3:a:thinkinai:deepchat:*:*:*:*:*:*:*:*

Wed, 10 Dec 2025 01:15:00 +0900

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 09 Dec 2025 19:15:00 +0900

Type Values Removed Values Added
First Time appeared Thinkinai
Thinkinai deepchat
Vendors & Products Thinkinai
Thinkinai deepchat

Tue, 09 Dec 2025 09:45:00 +0900

Type Values Removed Values Added
Description DeepChat is an open-source AI chat platform that supports cloud models and LLMs. Versions 0.5.1 and below are vulnerable to XSS attacks through improperly sanitized Mermaid content. The recent security patch for MermaidArtifact.vue is insufficient and can be bypassed using unquoted HTML attributes combined with HTML entity encoding. Remote Code Execution is possible on the victim's machine via the electron.ipcRenderer interface, bypassing the regex filter intended to strip dangerous attributes. There is no fix at time of publication.
Title DeepChat's Incomplete XSS Fix Allows RCE through Mermaid Content
Weaknesses CWE-79
CWE-80
CWE-94
References
Metrics cvssV3_1

{'score': 9.7, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2025-12-09T16:03:38.736Z

Reserved: 2025-12-02T17:09:52.016Z

Link: CVE-2025-66481

cve-icon Vulnrichment

Updated: 2025-12-09T14:17:48.212Z

cve-icon NVD

Status : Analyzed

Published: 2025-12-09T01:16:55.140

Modified: 2025-12-11T18:47:33.520

Link: CVE-2025-66481

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2025-12-09T19:04:36Z

Weaknesses