---
id: CVE-2025-67744
title: >-
  DeepChat is an open-source artificial intelligence agent platform that unifies
  models, tools, and agents
summary: >-
  DeepChat is an open-source artificial intelligence agent platform that unifies
  models, tools, and agents. Prior to version 0.5.3, a security vulnerability
  exists in the Mermaid diagram rendering component that allows arbitrary
  JavaScript…
severity: critical
cvss: 9.6
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H'
cwe:
  - CWE-94
vendor: thinkinai
product: deepchat
affected:
  - deepchat < 0.5.3
patched:
  - deepchat 0.5.3
published: '2025-12-16'
updated: '2026-10-07'
sourceUpdated: '2026-10-07T19:10:00.160'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-67744'
references:
  - url: >-
      https://github.com/ThinkInAIXYZ/deepchat/commit/b179d97921af04a0ae1ae68757338dd8b8cbefe7
    label: security-advisories@github.com
  - url: >-
      https://github.com/ThinkInAIXYZ/deepchat/security/advisories/GHSA-w8w8-82pv-5rg9
    label: security-advisories@github.com
tags:
  - nvd
epss: 0.00634
epssPercentile: 0.48673
ingestedAt: '2026-10-07T20:46:46.944Z'
---

## Overview

DeepChat is an open-source artificial intelligence agent platform that unifies models, tools, and agents. Prior to version 0.5.3, a security vulnerability exists in the Mermaid diagram rendering component that allows arbitrary JavaScript execution. Due to the exposure of the Electron IPC renderer to the DOM, this Cross-Site Scripting (XSS) flaw escalates to full Remote Code Execution (RCE), allowing an attacker to execute arbitrary system commands. Two concurrent issues, unsafe Mermaid configuration and an exposed IPC interface, cause this issue. Version 0.5.3 contains a patch.

## Affected

- `deepchat < 0.5.3`

## Remediation

Upgrade past the affected range:

- `deepchat 0.5.3`
