CVE-2025-55733: DeepChat One-click Remote Code Execution through Custom URL Handling
DeepChat is a smart assistant that connects powerful AI to your personal world. DeepChat before 0.3.1 has a one-click remote code execution vulnerability. An attacker can exploit this vulnerability by embedding a specially crafted deepchat: URL on any website, including a malicious one they control. When a victim visits such a site or clicks on the link, the browser triggers the app’s custom URL handler (deepchat:), causing the DeepChat application to launch and process the URL, leading to remote code execution on the victim’s machine. This vulnerability is fixed in 0.3.1.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2025-55733?
CVE-2025-55733 has a high severity due to its potential for remote code execution.
How can I mitigate the risk of CVE-2025-55733?
To mitigate CVE-2025-55733, you should upgrade DeepChat to version 0.3.1 or higher immediately.
What type of vulnerability is CVE-2025-55733?
CVE-2025-55733 is classified as a remote code execution vulnerability.
Who is affected by CVE-2025-55733?
CVE-2025-55733 affects all versions of DeepChat prior to 0.3.1.
What exploitation method is used for CVE-2025-55733?
CVE-2025-55733 can be exploited through a specially crafted deepchat: URL.