External risk intelligence

DeepChat RCE via XSS in Mermaid Rendering Component.

CVE advisorySeverity: CRITICAL (CVSS 9.6)

CVE-2025-67744

DeepChat is an artificial intelligence agent platform. While such platforms can be deployed as internet-facing services, they are also frequently used in local, developer-centric, or internal research environments. Because the vulnerability involves a component for rendering diagrams within an Electron-based application, exposure depends heavily on the specific deployment context, which is not inherently public-facing.

Code Injection

Thinkinai Deepchat

before 0.5.3

Halo Surface Signal: 3 out of 5 — possibly public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

A security vulnerability in the DeepChat AI platform, specifically in how it renders diagrams, could allow an attacker to execute arbitrary system commands. This flaw arises from how the platform handles user input and interacts with its underlying system, potentially leading to unauthorized actions if exploited. The primary concern is confirming whether this platform is in use and if it is exposed to risks.

  • Flaw lets attackers run commands on systems.
  • Matters if your teams use AI diagramming tools.
  • Confirm use and exposure to understand impact.

Attack Path

How an attacker could exploit the issue

An attacker could exploit this vulnerability by tricking a user into viewing a crafted message within the DeepChat platform. This message would trigger the vulnerable Mermaid diagram rendering component, allowing arbitrary JavaScript to execute. Because the platform uses Electron, this script can then interact with system commands, leading to remote code execution.

  • Requires user interaction to view a crafted message.
  • Triggers arbitrary JavaScript via a diagram rendering flaw.
  • Risk of arbitrary system command execution.

Live Threat

Current exploitation, exposure, and threat context

This vulnerability could allow an attacker to execute arbitrary system commands when a user views a crafted Mermaid diagram within DeepChat. This is possible due to unsafe configuration of the Mermaid rendering component and an exposed Electron IPC interface, which together enable cross-site scripting to escalate to remote code execution.

  • Arbitrary system command execution.
  • User views malicious diagram.
  • System compromise.

Operational Fix

Recommended remediation, mitigation, and detection steps

The DeepChat platform, specifically its Mermaid diagram rendering component, is affected by a critical vulnerability leading to Remote Code Execution. Application owners or the platform team responsible for DeepChat deployments should initiate an immediate inventory of all instances, prioritizing those exposed externally or handling sensitive data. Confirming asset ownership and assessing business criticality will guide the remediation plan, potentially involving vendor coordination if the affected version is integrated into a managed service.

  • Identify accountable DeepChat owners.
  • Verify external reachability and critical systems.
  • Plan coordinated updates or mitigation.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is DeepChat?

DeepChat is an open-source platform designed to unify various artificial intelligence models, tools, and agents into a single interface. It is built using Electron, a framework that allows web technologies to run as desktop applications, which is why it includes features like diagram rendering that interact directly with your computer's operating system.

How does CVE-2025-67744 lead to command execution?

This vulnerability is a form of Improper Control of Generation of Code, classified as CWE-94. It happens because the Mermaid diagram component is configured unsafely, allowing it to execute unauthorized JavaScript. Because the application uses Electron, this JavaScript can bridge the gap between the web interface and the underlying system, turning a browser-based scripting flaw into the ability to run arbitrary system commands.

Do I need to be tricked into clicking something to trigger this?

Yes. An attacker must successfully influence a user to view a specially crafted message containing a malicious Mermaid diagram within the platform. Simply having the software installed or running does not automatically trigger the vulnerability; it requires this specific interaction to initiate the rendering process that executes the harmful script.

How relevant is CVE-2025-67744 to my environment?

According to Halo Surface Signal, relevance depends on your deployment. While some AI platforms are placed on the open internet, many are used for internal research or local development. If your instance is internet-facing, it faces a higher risk of being targeted. You should evaluate whether your specific installation is accessible to untrusted users or restricted to your internal network.

What is the first step to fix this vulnerability?

The most effective action is to update your DeepChat installation to version 0.5.3 or later, which contains the patch for the rendering flaw. Before updating, identify all instances of DeepChat in your environment to ensure nothing is missed, and prioritize patching deployments that handle sensitive information or are accessible outside of your secure internal network.

References