CVE-2025-66222
critical · 9.6DeepChat is a smart assistant uses artificial intelligence. In 0.5.0 and earlier, there is a Stored Cross-Site Scripting (XSS) vulnerability in the Mermaid diagram renderer allows an attacker to execute arbitrary JavaScript within the application context. By leveraging the exposed Electron IPC bridge, this XSS can be escalated to Remote Code Execution (RCE) by registering and starting a malicious MCP (Model Context Protocol) server.
9.6
CVSS
0.6%
EPSS (exploit prob.)
48th
EPSS percentile
2025-12-03
Published
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
Weaknesses
CWE-94CWE-79
Affected products
| Vendor | Product | Affected versions |
|---|---|---|
| thinkinai | deepchat | <= 0.5.0 |
Check a specific version with /api/v1/cve/match.
References
Query this programmatically:
curl https://evil-db.io/api/v1/cve/CVE-2025-66222