DeepChat is a smart assistant that connects powerful AI to your personal world. DeepChat before 0.3.1 has a one-click remote code execution vulnerability. An attacker can exploit this vulnerability by embedding a specially crafted deepchat: URL on any website, including a malicious one they control. When a victim visits such a site or clicks on the link, the browser triggers the app’s custom URL handler (deepchat:), causing the DeepChat application to launch and process the URL, leading to remote code execution on the victim’s machine. This vulnerability is fixed in 0.3.1.
Metrics
Affected Vendors & Products
References
History
Wed, 17 Sep 2025 18:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Thinkinai
Thinkinai deepchat |
|
| CPEs | cpe:2.3:a:thinkinai:deepchat:0.3.0:*:*:*:*:*:*:* | |
| Vendors & Products |
Thinkinai
Thinkinai deepchat |
Tue, 19 Aug 2025 21:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 19 Aug 2025 18:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | DeepChat is a smart assistant that connects powerful AI to your personal world. DeepChat before 0.3.1 has a one-click remote code execution vulnerability. An attacker can exploit this vulnerability by embedding a specially crafted deepchat: URL on any website, including a malicious one they control. When a victim visits such a site or clicks on the link, the browser triggers the app’s custom URL handler (deepchat:), causing the DeepChat application to launch and process the URL, leading to remote code execution on the victim’s machine. This vulnerability is fixed in 0.3.1. | |
| Title | DeepChat One-click Remote Code Execution through Custom URL Handling | |
| Weaknesses | CWE-94 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2025-08-19T20:49:59.391Z
Reserved: 2025-08-14T22:31:17.683Z
Link: CVE-2025-55733
Updated: 2025-08-19T20:49:30.413Z
Status : Analyzed
Published: 2025-08-19T19:15:37.260
Modified: 2025-09-17T17:58:46.877
Link: CVE-2025-55733
No data.