External risk intelligence

DeepChat Cross-Site Scripting and Remote Code Execution Vulnerability.

CVE advisorySeverity: CRITICAL (CVSS 9.6)

CVE-2025-66481

DeepChat is an open-source AI chat platform. These platforms are typically deployed as web applications or user-facing services intended for interaction with external users, making them commonly reachable from the internet.

Cross-site Scripting

Thinkinai Deepchat

0.5.1 and earlier

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

A security vulnerability in the DeepChat AI platform, specifically in versions prior to 0.5.1, allows for cross-site scripting attacks that could potentially lead to remote code execution. While a patch was issued, it is insufficient and can be bypassed, leaving the platform at risk.

  • Vulnerability in AI chat platform allows code execution.
  • Unpatched flaw allows bypassing security filters.
  • Confirm if this AI platform is in use.

Attack Path

How an attacker could exploit the issue

An attacker could target users of the DeepChat AI platform by tricking them into viewing specially crafted content. This content, which bypasses security filters designed to protect against cross-site scripting, could then be used to execute code on the victim's system through a communication channel.

  • No special access required.
  • User views malicious content.
  • Code execution on victim's machine.

Live Threat

Current exploitation, exposure, and threat context

DeepChat versions prior to 0.5.1 are vulnerable to cross-site scripting (XSS) when processing improperly sanitized Mermaid content. Attackers can bypass security filters, potentially leading to remote code execution on a victim's machine.

  • User input and system data could be compromised.
  • Exploitation may occur through crafted web content.
  • Victim machines could face unauthorized control.

Operational Fix

Recommended remediation, mitigation, and detection steps

This vulnerability impacts DeepChat deployments, likely managed by platform or application teams responsible for AI services. The immediate first step is to identify all instances of DeepChat within your environment, assess their internet reachability and criticality, and locate the designated owner for each instance to plan appropriate mitigation or remediation.

  • Platform or application teams own this issue.
  • Verify affected DeepChat instances and exposure.
  • Plan remediation based on confirmed risk.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is DeepChat?

DeepChat is an open-source platform designed for AI chat interactions. It enables users to integrate and communicate with various cloud-based models and Large Language Models (LLMs). It often runs as a web application, allowing developers and organizations to build custom chatbot interfaces for their own services or user-facing tools.

How does CVE-2025-66481 create a vulnerability?

The vulnerability involves improper neutralization of input, specifically within Mermaid content rendering. This is categorized as Cross-Site Scripting (CWE-79) and Improper Neutralization of Script-Related HTML Tags (CWE-80). Because the platform uses the electron.ipcRenderer interface, this flaw can be escalated to Code Injection (CWE-94), allowing unauthorized commands to run on the underlying system.

Do I need to interact with the system to trigger this?

Yes, an attacker must induce a user to view specially crafted, malicious Mermaid content within the application. The vulnerability is not triggered by simple network scans or background connectivity. It requires the application to process and render the specific, malicious input provided by an attacker, which bypasses existing security filters through encoded HTML attributes.

Why does Halo Surface Signal categorize this as likely relevant?

Halo Surface Signal identifies this as likely relevant because DeepChat is an AI chat platform designed for user interaction. These services are typically deployed as internet-facing web applications to facilitate public or broad organizational access. Because it is meant to be reachable by users, the potential for an attacker to present malicious content is significantly higher.

What should I do if I use DeepChat?

First, locate and inventory all instances of DeepChat in your environment to understand your footprint. Since there is no official fix yet, assess the internet-facing risk of each instance. Coordinate with your application owners to monitor for security updates from the maintainers and consider restricting access to trusted users until a robust patch is released.

References