Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-27502 | DeepChat is a smart assistant uses artificial intelligence. Prior to version 0.3.5, in the Mermaid chart rendering component, there is a risky operation of directly using `innerHTML` to set user content. Therefore, any malicious content rendered via Mermaid will directly trigger the exploit chain, leading to command execution. This vulnerability is primarily caused by a failure to fully address the existing XSS issue in the project, leading to another exploit chain. The exploit chain is consistent with the report GHSA-hqr4-4gfc-5p2j, executing arbitrary JavaScript code via XSS and arbitrary commands via exposed IPC. Version 0.3.5 contains an updated fix. |
Thu, 18 Sep 2025 20:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Thinkinai
Thinkinai deepchat |
|
| Weaknesses | CWE-79 | |
| CPEs | cpe:2.3:a:thinkinai:deepchat:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Thinkinai
Thinkinai deepchat |
Tue, 09 Sep 2025 23:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 09 Sep 2025 20:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | DeepChat is a smart assistant uses artificial intelligence. Prior to version 0.3.5, in the Mermaid chart rendering component, there is a risky operation of directly using `innerHTML` to set user content. Therefore, any malicious content rendered via Mermaid will directly trigger the exploit chain, leading to command execution. This vulnerability is primarily caused by a failure to fully address the existing XSS issue in the project, leading to another exploit chain. The exploit chain is consistent with the report GHSA-hqr4-4gfc-5p2j, executing arbitrary JavaScript code via XSS and arbitrary commands via exposed IPC. Version 0.3.5 contains an updated fix. | |
| Title | DeepChat's Mermaid rendering has XSS leading to RCE | |
| Weaknesses | CWE-94 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2025-09-09T20:31:54.042Z
Reserved: 2025-09-04T19:18:09.501Z
Link: CVE-2025-58768
Updated: 2025-09-09T20:31:44.125Z
Status : Analyzed
Published: 2025-09-09T21:15:38.957
Modified: 2025-09-18T20:26:13.443
Link: CVE-2025-58768
No data.
OpenCVE Enrichment
No data.
EUVD