CVE-2025-66222: DeepChat Cross-Site Scripting(XSS) escalate to Remote Code Execution(RCE)
DeepChat is a smart assistant uses artificial intelligence. In 0.5.0 and earlier, there is a Stored Cross-Site Scripting (XSS) vulnerability in the Mermaid diagram renderer allows an attacker to execute arbitrary JavaScript within the application context. By leveraging the exposed Electron IPC bridge, this XSS can be escalated to Remote Code Execution (RCE) by registering and starting a malicious MCP (Model Context Protocol) server.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2025-66222?
CVE-2025-66222 is considered a high severity vulnerability due to its potential for executing arbitrary JavaScript via stored XSS.
How do I fix CVE-2025-66222?
To fix CVE-2025-66222, upgrade DeepChat to version 0.5.1 or later to eliminate the stored XSS vulnerability.
What systems are affected by CVE-2025-66222?
CVE-2025-66222 affects DeepChat versions up to and including 0.5.0.
What type of attack does CVE-2025-66222 enable?
CVE-2025-66222 enables attackers to perform stored cross-site scripting (XSS) attacks within the application context.
Who should be concerned about CVE-2025-66222?
Developers and administrators using DeepChat version 0.5.0 or earlier should be concerned about CVE-2025-66222 and take immediate action to mitigate risks.