← Back

CVE-2025-66222

nvd nist
Published: Dec 3, 2025Modified: Jun 17, 2026

JSON object

Loading...
9.6
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
Exploitability: 2.8 / Impact: 6.0
Source: NVD

Description

DeepChat is a smart assistant uses artificial intelligence. In 0.5.0 and earlier, there is a Stored Cross-Site Scripting (XSS) vulnerability in the Mermaid diagram renderer allows an attacker to execute arbitrary JavaScript within the application context. By leveraging the exposed Electron IPC bridge, this XSS can be escalated to Remote Code Execution (RCE) by registering and starting a malicious MCP (Model Context Protocol) server.

Affected (1)

Products: Thinkinai: Deepchat
1 product
Deepchat
Configuration A
1 vulnerable
Vulnerable SoftwareAffected Versions
Up to 0.5.0

References (2)

Timeline

No history available yet.